CVE-2006-2659

6 documents6 sources
Severity
7.8HIGH
EPSS
3.6%
top 12.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 30
Latest updateMay 1

Description

libs/comverp.c in Courier MTA before 0.53.2 allows attackers to cause a denial of service (CPU consumption) via unknown vectors involving usernames that contain the "=" (equals) character, which is not properly handled during encoding.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages2 packages

Debiancourier< 0.53.2-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-jf3h-hc4x-5q33: libs/comverp2022-05-01
CVEList
CVE-2006-2659: libs/comverp2006-05-30
OSV
CVE-2006-2659: libs/comverp2006-05-30

📋Vendor Advisories

2
Ubuntu
courier vulnerability2006-06-09
Debian
CVE-2006-2659: courier - libs/comverp.c in Courier MTA before 0.53.2 allows attackers to cause a denial o...2006
CVE-2006-2659 (HIGH CVSS 7.8) | libs/comverp.c in Courier MTA befor | cvebase.io