MEDIUM · 5.0

CVE-2006-3216

Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange before 4.3.20 allows remote attackers to cause a denial of service via (1) non-ASCII characters in a reverse DNS lookup resul...

Vulnerability Description

Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange before 4.3.20 allows remote attackers to cause a denial of service via (1) non-ASCII characters in a reverse DNS lookup result from a Received header, which leads to a Receiver service stop, and (2) unspecified vectors involving malformed messages, which causes "unpredictable behavior" that prevents the Security service from processing more messages.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
ClearswiftMailsweeper For Exchange<= 4.3.19
ClearswiftMailsweeper For Smtp<= 4.3.19

References

FAQ

What is CVE-2006-3216?

CVE-2006-3216 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange before 4.3.20 allows remote attackers to cause a denial of service via (1) non-ASCII characters in a reverse DNS lookup resul...

How severe is CVE-2006-3216?

CVE-2006-3216 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-3216?

Check the references section above for vendor advisories and patch information. Affected products include: Clearswift Mailsweeper For Exchange, Clearswift Mailsweeper For Smtp.