CVE-2006-6554: Medium severity kerio kerio mailserver vulnerability
Published Dec 14, 2006
·Updated
Unspecified vulnerability in Kerio MailServer before 6.3.1 allows remote attackers to cause a denial of service (segmentation fault and service stop) via certain long LDAP queries, as demonstrated by vdkms6.pm.
Affected Software
29 affected components
Kerio Kerio MailServer<=6.3.0
Kerio Kerio MailServer=5.0
Kerio Kerio MailServer=5.1
Kerio Kerio MailServer=5.1.1
Kerio Kerio MailServer=5.6.3
Kerio Kerio MailServer=5.6.4
Kerio Kerio MailServer=5.6.5
Kerio Kerio MailServer=5.7.0
Kerio Kerio MailServer=5.7.1
Kerio Kerio MailServer=5.7.2
Kerio Kerio MailServer=5.7.3
Kerio Kerio MailServer=5.7.4
Kerio Kerio MailServer=5.7.5
Kerio Kerio MailServer=5.7.6
Kerio Kerio MailServer=5.7.7
Kerio Kerio MailServer=5.7.8
Kerio Kerio MailServer=5.7.9
Kerio Kerio MailServer=5.7.10
Kerio Kerio MailServer=6.0
Kerio Kerio MailServer=6.0.0
Kerio Kerio MailServer=6.0.1
Kerio Kerio MailServer=6.0.2
Kerio Kerio MailServer=6.0.3
Kerio Kerio MailServer=6.0.4
Kerio Kerio MailServer=6.0.5
Kerio Kerio MailServer=6.0.6
Kerio Kerio MailServer=6.0.7
Kerio Kerio MailServer=6.0.8
Kerio Kerio MailServer=6.1.3_patch_1
Remediation
Patch Available
Patch Available
Event History
Dec 14, 2006
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:28 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-6554?
CVE-2006-6554 is classified as a denial of service vulnerability that can lead to service interruption.
2
How do I fix CVE-2006-6554?
To fix CVE-2006-6554, upgrade Kerio MailServer to version 6.3.1 or later.
3
What versions of Kerio MailServer are affected by CVE-2006-6554?
CVE-2006-6554 affects Kerio MailServer versions prior to 6.3.1.
4
What is the impact of CVE-2006-6554?
The impact of CVE-2006-6554 is the potential for a remote attacker to cause a segmentation fault and stop the service.
5
How can I determine if my Kerio MailServer is vulnerable to CVE-2006-6554?
Check the version of your Kerio MailServer against version 6.3.1 or later to determine if it is vulnerable to CVE-2006-6554.