First published: Sat Jun 24 2006(Updated: )
Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange before 4.3.20 allows remote attackers to cause a denial of service via (1) non-ASCII characters in a reverse DNS lookup result from a Received header, which leads to a Receiver service stop, and (2) unspecified vectors involving malformed messages, which causes "unpredictable behavior" that prevents the Security service from processing more messages.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Clearswift MAILsweeper for Exchange | <=4.3.19 | |
Clearswift MAILsweeper | <=4.3.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3216 has been identified as having a denial of service impact.
To mitigate CVE-2006-3216, upgrade to Clearswift MAILsweeper for SMTP and Exchange version 4.3.20 or later.
CVE-2006-3216 affects Clearswift MAILsweeper for SMTP and Exchange versions prior to 4.3.20.
CVE-2006-3216 facilitates a denial of service attack through non-ASCII characters in DNS lookup results.
Yes, CVE-2006-3216 can be exploited remotely, allowing attackers to stop the Receiver service.