When adding an external mail account, processing of SMTP capabilities responses are not limited to plausible sizes. Attacker with access to a rogue SMTP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted SMTP server response to reasonable length/size. No publicly available exploits are known.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Open-xchange_appsuite_backend | Open-xchange | * | 7.10.6 (excluding) |
Open-xchange_appsuite_backend | Open-xchange | 8.0.0 (including) | 8.11.0 (excluding) |
Open-xchange_appsuite_backend | Open-xchange | 7.10.6 (including) | 7.10.6 (including) |
Open-xchange_appsuite_backend | Open-xchange | 7.10.6-revision_39 (including) | 7.10.6-revision_39 (including) |