eXtremail 2.1.1 and earlier does not verify the ID field (aka transaction id) in DNS responses, which makes it easier for remote attackers to conduct DNS spoofing.
Link | Tags |
---|---|
http://osvdb.org/35584 | vdb entry |
http://www.securityfocus.com/bid/23577 | vdb entry |
http://archives.neohapsis.com/archives/fulldisclosure/2007-04/0569.html | mailing list exploit |