Kerio MailServer IMAP Server Crafted LOGIN Command DoS

This script is Copyright (C) 2006-2017 Tenable Network Security, Inc.


Synopsis :

The remote IMAP server is prone to denial of service attacks.

Description :

The remote host is running Kerio MailServer, a commercial mail server
available for Windows, Linux, and Mac OS X platforms.

The installed version of Kerio MailServer terminates abnormally when
it receives certain malformed IMAP LOGIN commands. An unauthenticated,
remote attacker can exploit this issue to deny access to legitimate
users.

Note that the application may not terminate immediately but only after
an administrator acknowledges a console message.

See also :

http://seclists.org/fulldisclosure/2006/Mar/701
http://www.kerio.com/kms_history.html

Solution :

Upgrade to Kerio MailServer 6.1.3 Patch 1 or later.

Risk factor :

High / CVSS Base Score : 7.8
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS Temporal Score : 5.8
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: Denial of Service

Nessus Plugin ID: 21050 (kerio_kms_imap_login_dos.nasl)

Bugtraq ID: 17043

CVE ID: CVE-2006-1158

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now