CVE-2006-7041: High severity Atrium Software Mercur Messaging 2005 vulnerability
Published Feb 23, 2007
·Updated
The SMTP service in MERCUR Messaging 2005 before Service Pack 4 allows remote attackers to cause a denial of service (infinite loop) via a message in which neither the originator nor recipient address is known.
Affected Software
3 affected components
Atrium Software Mercur Messaging 2005=5.0_sp3
Atrium Software Mercur Messaging 2005=5.0_sp3
Atrium Software Mercur Messaging 2005=5.0_sp3
Event History
Feb 23, 2007
CVE Published
03:28 AM
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-7041?
CVE-2006-7041 is classified as a denial of service vulnerability.
2
How do I fix CVE-2006-7041?
To mitigate CVE-2006-7041, upgrade MERCUR Messaging 2005 to Service Pack 4 or later.
3
What types of attacks can exploit CVE-2006-7041?
CVE-2006-7041 can be exploited by sending specially crafted messages with unknown originator and recipient addresses.
4
Which versions of MERCUR Messaging are affected by CVE-2006-7041?
CVE-2006-7041 affects MERCUR Messaging 2005 versions prior to Service Pack 4.
5
What impact does CVE-2006-7041 have on my system?
Exploitation of CVE-2006-7041 can lead to an infinite loop, resulting in a denial of service.