CVE-2008-1275: High severity mailenable enterprise vulnerability
Multiple unspecified vulnerabilities in the SMTP service in MailEnable Standard Edition 1.x, Professional Edition 3.x and earlier, and Enterprise Edition 3.x and earlier allow remote attackers to cause a denial of service (crash) via crafted (1) EXPN or (2) VRFY commands.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1275?
CVE-2008-1275 is considered a denial of service vulnerability which can lead to crashes in MailEnable services.
How do I fix CVE-2008-1275?
To fix CVE-2008-1275, update MailEnable to a version later than 3.0 of Professional or Enterprise editions, or a fixed version if available.
Which versions of MailEnable are affected by CVE-2008-1275?
CVE-2008-1275 affects MailEnable Standard Edition 1.x, and both Professional and Enterprise Editions 3.x and earlier.
What attacks can occur through CVE-2008-1275?
CVE-2008-1275 allows attackers to execute crafted EXPN or VRFY commands, resulting in a denial of service.
Is there a workaround for CVE-2008-1275?
Currently, the best approach for CVE-2008-1275 is to upgrade to a non-vulnerable version of MailEnable.