First published: Fri Feb 23 2007(Updated: )
Multiple buffer overflows in MERCUR Messaging 2005 before Service Pack 4 allow remote attackers to cause a denial of service (crash) via (1) "long command lines at port 32000" and (2) certain name service queries that are not properly handled by the SMTP service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Atrium Software Mercur Messaging 2005 | =5.0_sp3 | |
Atrium Software Mercur Messaging 2005 | =5.0_sp3 | |
Atrium Software Mercur Messaging 2005 | =5.0_sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-7038 is classified as a high severity vulnerability due to its potential to cause denial of service.
To mitigate CVE-2006-7038, update MERCUR Messaging 2005 to Service Pack 4 or later.
CVE-2006-7038 can be exploited through long command lines sent to port 32000 and malformed name service queries to the SMTP service.
CVE-2006-7038 affects all versions of MERCUR Messaging 2005 before Service Pack 4, including 5.0 SP3.
CVE-2006-7038 does not cause permanent damage but can lead to service disruption through crashes.