Description: rgod has discovered a vulnerability in SurgeMail, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to a boundary error within the processing of "Host" HTTP headers. This can be exploited to cause a stack-based buffer overflow via a specially crafted HTTP request with an overly-long (greater than 1000 bytes) "Host" header.
The vulnerability is confirmed in version 38k4. Other versions may also be affected.
Solution: Restrict network access to the webmail service.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.