Junglewise Threat Intelligence

CVE-1999-0272: Seattle Lab SLMail denial of service in POP3 service

CVE-1999-0272 · Severity: medium · CVSS 5 · Published 1997-10-01

Executive brief

A vulnerability in the SLMail email server allows remote attackers to disrupt email services. By sending specific requests to the POP3 port, an attacker can cause the mail server to crash or become unresponsive. This prevents users from accessing their incoming email and can interrupt business communications.

Technical details

A denial of service vulnerability exists in Seattle Lab SLMail version 2.5. The flaw is located in the POP3 service handling, where unauthenticated remote attackers can send malformed or specific sequences of commands to the POP3 port (typically TCP 110). Successful exploitation causes the service to hang or crash, resulting in a loss of availability for email retrieval. No authentication is required to trigger the condition.

Affected products

  • Seattle Lab SLMail 2.5

Timeline

  • 1997-10-01: disclosed: Initial publication date

References