Vulnerability Name: | CVE-1999-0945 (CCN-1223) | ||||||||
Assigned: | 1998-07-24 | ||||||||
Published: | 1998-07-24 | ||||||||
Updated: | 2020-04-02 | ||||||||
Summary: | Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of service via AUTH or AUTHINFO commands. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||
Vulnerability Type: | CWE-120 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: CCN Type: CIAC Information Bulletin I-080 Microsoft Exchange Denial of Service Attacks Source: MITRE Type: CNA CVE-1999-0945 Source: MITRE Type: CNA CVE-1999-1043 Source: MSKB Type: Patch, Vendor Advisory Q169174 Source: CIAC Type: Patch, Vendor Advisory I-080 Source: CCN Type: Internet Security Systems Security Alert #04 Denial of Service attacks against Microsoft Exchange 5.0 to 5.5 Source: CCN Type: Microsoft Corporation Web site Microsoft Servers - Exchange Server Home Source: CCN Type: Microsoft Security Bulletin MS98-007 Potential SMTP and NNTP Denial-of-Service Vulnerabilities in Microsoft Exchange Server Source: CCN Type: OSVDB ID: 10246 Microsoft Exchange Server Malformed NNTP AUTHINFO DoS Source: CCN Type: OSVDB ID: 11268 Microsoft Exchange Internet Mail Service AUTH/AUTHINFO Command DoS Source: CCN Type: OSVDB ID: 8211 Microsoft Exchange Server Malformed SMTP Command DoS Source: CCN Type: BID-924 Microsoft Exchange Server AUTH / XAUTH / AUTHINFO DoS Vulnerabilities Source: ISS Type: Patch, Vendor Advisory 19980724 Denial of Service attacks against Microsoft Exchange 5.0 to 5.5 Source: XF Type: UNKNOWN exchange-dos(1223) Source: XF Type: VDB Entry exchange-dos(1223) Source: CCN Type: Microsoft Knowledge Base Article 169174 XFOR: IMS Halts if RFC821 Address Over 1k in Size is Received Source: CCN Type: Microsoft Knowledge Base Article 188341 XFOR: AUTH and EHLO Commands Cause Internet Mail Service to Stop Source: CCN Type: Microsoft Knowledge Base Article 188369 XADM: AUTHINFO Command Causes Information Store Problems | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |