7.8

CVE-2007-1669

Exploit

zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.

Data is provided by the National Vulnerability Database (NVD)
AmavisAmavis Version <= 2.4.1
   Barracuda NetworksBarracuda Spam Firewall Version3.1.17
   Barracuda NetworksBarracuda Spam Firewall Version3.1.18
   Barracuda NetworksBarracuda Spam Firewall Version3.3.0.54
   Barracuda NetworksBarracuda Spam Firewall Version3.3.01.001
   Barracuda NetworksBarracuda Spam Firewall Version3.3.3
   Barracuda NetworksBarracuda Spam Firewall Version3.3.03.053
   Barracuda NetworksBarracuda Spam Firewall Version3.3.03.055
   Barracuda NetworksBarracuda Spam Firewall Version3.3.15.026
   Barracuda NetworksBarracuda Spam Firewall Version3.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 15.91% 0.941
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C