CVE-2010-2580: Input Validation
The SMTP service (MESMTPC.exe) in MailEnable 3.x and 4.25 does not properly perform a length check, which allows remote attackers to cause a denial of service (crash) via a long (1) email address in the MAIL FROM command, or (2) domain name in the RCPT TO command, which triggers an "unhandled invalid parameter error."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2580?
CVE-2010-2580 is classified as a denial-of-service vulnerability affecting MailEnable versions 3.x and 4.x.
How do I fix CVE-2010-2580?
To fix CVE-2010-2580, update MailEnable to the latest version that has patched this vulnerability.
Which versions of MailEnable are affected by CVE-2010-2580?
CVE-2010-2580 affects MailEnable versions from 3.0 up to 4.25.
What type of attack can exploit CVE-2010-2580?
CVE-2010-2580 can be exploited by sending a long email address in the MAIL FROM command or a long domain name in the RCPT TO command.
What is the impact of CVE-2010-2580?
The impact of CVE-2010-2580 is a potential denial of service, leading to a crash of the SMTP service.