Kerio MailServer < 6.3.1 Long LDAP Query DoS

This script is Copyright (C) 2006-2012 Tenable Network Security, Inc.


Synopsis :

The remote LDAP server is prone to a denial of service attack.

Description :

The remote host is running Kerio MailServer, a commercial mail server
available for Windows, Linux, and Mac OS X platforms.

According to its banner, the LDAP service associated with the
installed version of Kerio MailServer terminates abnormally when it
receives certain malformed LDAP search requests. An unauthenticated,
remote attacker can exploit this issue to deny access to legitimate
users.

See also :

http://www.securityfocus.com/archive/1/454455/30/0/threaded
http://forums.kerio.com/index.php?t=msg&th=10321&start=0

Solution :

Upgrade to Kerio MailServer 6.3.1 or later.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS Temporal Score : 4.1
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Denial of Service

Nessus Plugin ID: 23868 (kerio_kms_631.nasl)

Bugtraq ID: 21091

CVE ID: CVE-2006-6554