The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a buffer overflow in Exchange 2000.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
http://www.cert.org/advisories/CA-2003-27.html | third party advisory us government resource |
http://marc.info/?l=bugtraq&m=106682909006586&w=2 | third party advisory mailing list |
http://www.kb.cert.org/vuls/id/422156 | us government resource third party advisory patch |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-046 | patch vendor advisory |
http://www.securityfocus.com/bid/8838 | patch exploit vdb entry third party advisory |