« Volver al listado

CVE-2008-1689

Estado: ModificadaMedia (5)—

Stack consumption vulnerability in WebContainer.exe 1.0.0.336 and earlier in SLMail Pro 6.3.1.0 and earlier allows remote attackers to cause a denial of service (daemon crash) via a long request header in an HTTP request to TCP port 801. NOTE: some of these details are obtained from third party information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-1689",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-04-07T17:44:00.000",
  "references": [
    {
      "url": "http://aluigi.altervista.org/adv/slmaildos-adv.txt",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://aluigi.org/poc/slmaildos.zip",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/29614",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/28505",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/1039/references",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41532",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://aluigi.altervista.org/adv/slmaildos-adv.txt",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://aluigi.org/poc/slmaildos.zip",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/29614",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/28505",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/1039/references",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41532",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-399"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Stack consumption vulnerability in WebContainer.exe 1.0.0.336 and earlier in SLMail Pro 6.3.1.0 and earlier allows remote attackers to cause a denial of service (daemon crash) via a long request header in an HTTP request to TCP port 801.  NOTE: some of these details are obtained from third party information."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de agotamiento de pila de WebContainer.exe 1.0.0.336 y versiones anteriores, en SLMail Pro 6.3.1.0 y versiones anteriores, permite a atacantes remotos provocar una denegación de servicio (caída del demonio) mediante una cabecera de una petición larga en una petición HTTP al puerto TCP 801. NOTA: algún detalle ha sido obtenido de información de terceros."
    }
  ],
  "lastModified": "2026-06-16T22:52:16.530",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:seattle_lab_software:slmail_pro:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B83A7AC1-E492-4449-8C06-F4CE960C6270",
              "versionEndIncluding": "6.3.1.0"
            },
            {
              "criteria": "cpe:2.3:a:seattle_lab_software:slmail_pro:5.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77FBD34A-2B93-4395-B0F2-7463468A32A3"
            },
            {
              "criteria": "cpe:2.3:a:seattle_lab_software:slmail_pro:6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "84C16CA7-DCD1-4907-829A-AAAF0DF195EF"
            },
            {
              "criteria": "cpe:2.3:a:seattle_lab_software:slmail_pro:6.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82DD3A64-12A7-41B1-A0E5-B352120BFDD2"
            },
            {
              "criteria": "cpe:2.3:a:seattle_lab_software:slmail_pro:6.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E7AB1FC0-B963-4160-A872-C9E1497EBF71"
            },
            {
              "criteria": "cpe:2.3:a:seattle_lab_software:slmail_pro:6.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2373EEB7-D1DA-4700-ACB2-1204B156DEC7"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "Only version information is located here: http://www.seattlelab.com/Products/SLMailPro/Utilities.asp. Versions 3.x, 4.x, and 5.x are vulnerable, but specific version information is not available.",
  "sourceIdentifier": "cve@mitre.org"
}