CVE-2010-0025 Information
Feb 14, 2021
cve
Description
The SMTP component in Microsoft Windows 2000 SP4 XP SP2 and SP3 Server 2003 SP2 and Server 2008 Gold SP2 and R2 and Exchange Server 2000 SP3 does not properly allocate memory for SMTP command replies which allows remote attackers to read fragments of e-mail messages by sending a series of invalid commands and then sending a STARTTLS command aka \SMTP Memory Allocation Vulnerability.\
Reference
http://secunia.com/advisories/39253 http://www.us-cert.gov/cas/techalerts/TA10-103A.html https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-024 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A12175
Share on: