Eudora Internet Mail Server (EIMS) < 3.2.8 Multiple DoS

This script is Copyright (C) 2006-2011 Tenable Network Security, Inc.


Synopsis :

The remote mail server is affected by multiple denial of service flaws.

Description :

The remote host appears to be running Eudora Internet Mail Server, a
mail server for Macs.

According to its banner, the version of Eudora Internet Mail Server
(EIMS) installed on the remote host is reportedly susceptible to denial
of service attacks involving malformed NTLM authentication requests as
well as corrupted incoming MailX and temporary mail files. While not
certain, the first issue is likely to be remotely exploitable.

See also :

http://www.eudora.co.nz/updates.html

Solution :

Upgrade to EIMS version 3.2.8 or later.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS Temporal Score : 4.2
(CVSS2#E:U/RL:U/RC:C)
Public Exploit Available : false

Family: SMTP problems

Nessus Plugin ID: 20394 (eims_328.nasl)

Bugtraq ID: 16179

CVE ID: CVE-2006-0141