Impact
Progressive Robot hMailServer 6.0.0 through 6.3.5 implements a header decoding routine that repeatedly scans the header from the end, moving data each time a line break is found. The time required grows roughly with the square of the number of line breaks in the decoded value, and an RFC 2047 encoded word can produce an arbitrary number of such breaks. As a result, a message with a specially crafted Subject or other header can cause a worker thread to spend minutes or longer processing that header each time it is read. The affected services—IMAP, SMTP, POP3, and webmail—share worker threads, so a single problematic message can halt all of them and also delay operations such as searching, sorting, threading, rule evaluation, and spam tag generation.
Affected Systems
The vulnerability affects all releases of hMailServer from 6.0.0 up to and including 6.3.5, regardless of platform. All primary mail protocols (IMAP, SMTP, POP3) and the webmail interface are impacted, as well as any rule or abuse reporting mechanisms that scan message headers. The issue is triggered when a message is received and later accessed by any of these interfaces.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity risk, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote and unauthenticated: an adversary can send a crafted message containing a large RFC 2047 encoded header field to the vulnerable server. Once the header is parsed, the server spends excessive CPU time, effectively denying service to all users interacting with that server. Because the exploitation does not require authentication, the impact scope spans any client using the affected protocols or webmail interface.
OpenCVE Enrichment