CVE-2006-7039: Medium severity Microsoft Windows 2000 vulnerability
Published Feb 23, 2007
·Updated
The IMAP4 service in MERCUR Messaging 2005 before Service Pack 4 allows remote attackers to cause a denial of service (crash) via a message with a long subject field.
Affected Software
11 affected components
Microsoft Windows 2000
Microsoft Windows 2003 Server=sp2
Microsoft Windows 95
Microsoft Windows 98=gold
Microsoft Windows 98SE
Microsoft Windows Me
Microsoft Windows NT=4.0
Microsoft Windows XP=gold
Atrium Software Mercur Messaging 2005=5.0_sp3
Atrium Software Mercur Messaging 2005=5.0_sp3
Atrium Software Mercur Messaging 2005=5.0_sp3
Event History
Feb 23, 2007
CVE Published
03:28 AM
Data Sourced
03:28 AM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-7039?
CVE-2006-7039 has a severity rating that indicates it can lead to a denial of service due to a crash of the IMAP4 service.
2
How do I fix CVE-2006-7039?
To fix CVE-2006-7039, upgrade the MERCUR Messaging software to Service Pack 4 or later.
3
What software is affected by CVE-2006-7039?
CVE-2006-7039 primarily affects Atrium Software Mercur Messaging 2005 versions prior to Service Pack 4.
4
Can CVE-2006-7039 be exploited remotely?
Yes, CVE-2006-7039 can be exploited remotely by sending a specially crafted message with a long subject field.
5
What types of systems are at risk due to CVE-2006-7039?
Systems running Atrium Software Mercur Messaging 2005 prior to Service Pack 4 are at risk from CVE-2006-7039.