Synopsis
The remote host has a application that is affected by a denial of service vulnerability.
Description
According to its banner, the remote host is running at least one instance of MailEnable's SMTP Connector service. A flaw exists in both the Standard Edition 1.7x and Professional Edition 1.2x/1.5a-e that results in this service crashing if it receives a DNS response with over 100 MX records. A remote attacker can exploit this to perform a DoS attack against the SMTP server on the target.
Solution
Upgrade to MailEnable Standard Edition 1.8 / Professional Edition 1.5e or greater.
Plugin Details
File Name: mailenable_smtp_dos.nasl
Configuration: Enable thorough checks
Supported Sensors: Nessus
Vulnerability Information
CPE: cpe:/a:mailenable:mailenable
Exploit Ease: No exploit is required
Vulnerability Publication Date: 9/9/2004
Reference Information
BID: 11144