CVE-2006-3216: Medium severity clearswift mailsweeper for smtp vulnerability
Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange before 4.3.20 allows remote attackers to cause a denial of service via (1) non-ASCII characters in a reverse DNS lookup result from a Received header, which leads to a Receiver service stop, and (2) unspecified vectors involving malformed messages, which causes "unpredictable behavior" that prevents the Security service from processing more messages.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3216?
CVE-2006-3216 has been identified as having a denial of service impact.
How do I fix CVE-2006-3216?
To mitigate CVE-2006-3216, upgrade to Clearswift MAILsweeper for SMTP and Exchange version 4.3.20 or later.
Which versions of MAILsweeper are affected by CVE-2006-3216?
CVE-2006-3216 affects Clearswift MAILsweeper for SMTP and Exchange versions prior to 4.3.20.
What type of attack does CVE-2006-3216 facilitate?
CVE-2006-3216 facilitates a denial of service attack through non-ASCII characters in DNS lookup results.
Can CVE-2006-3216 be exploited remotely?
Yes, CVE-2006-3216 can be exploited remotely, allowing attackers to stop the Receiver service.