6.8

CVE-2007-4578

Sophos Anti-Virus for Windows and for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted UPX packed file, resulting from an "integer cast around".  NOTE: as of 20070828, the vendor says this is a DoS and the researcher says this allows code execution, but the researcher is reliable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sophos ≫ Anti-virus Version 3.4.6
Sophos ≫ Anti-virus Version 3.78
Sophos ≫ Anti-virus Version 3.78d
Sophos ≫ Anti-virus Version 3.79
Sophos ≫ Anti-virus Version 3.80
Sophos ≫ Anti-virus Version 3.81
Sophos ≫ Anti-virus Version 3.82
Sophos ≫ Anti-virus Version 3.83
Sophos ≫ Anti-virus Version 3.84
Sophos ≫ Anti-virus Version 3.85
Sophos ≫ Anti-virus Version 3.86
Sophos ≫ Anti-virus Version 3.90
Sophos ≫ Anti-virus Version 3.91
Sophos ≫ Anti-virus Version 3.95
Sophos ≫ Anti-virus Version 3.96.0
Sophos ≫ Anti-virus Version 4.03 Edition linux
Sophos ≫ Anti-virus Version 4.04
Sophos ≫ Anti-virus Version 4.05
Sophos ≫ Anti-virus Version 4.5.3
Sophos ≫ Anti-virus Version 4.5.4
Sophos ≫ Anti-virus Version 4.5.11
Sophos ≫ Anti-virus Version 4.5.12
Sophos ≫ Anti-virus Version 4.7.1
Sophos ≫ Anti-virus Version 4.7.2
Sophos ≫ Anti-virus Version 5.0.1
Sophos ≫ Anti-virus Version 5.0.2
Sophos ≫ Anti-virus Version 5.0.4
Sophos ≫ Anti-virus Version 5.0.9
Sophos ≫ Anti-virus Version 5.0.9 Edition linux
Sophos ≫ Anti-virus Version 5.1
Sophos ≫ Anti-virus Version 5.2
Sophos ≫ Anti-virus Version 5.2.1
Sophos ≫ Anti-virus Version 6.5
Sophos ≫ Scanning Engine Version 2.30.4
Sophos ≫ Scanning Engine Version 2.40.2
Sophos ≫ Small Business Suite Version 4.04
Sophos ≫ Small Business Suite Version 4.05
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.3% 0.936
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/26580
Patch
Vendor Advisory
http://securitytracker.com/id?1018608
http://www.securityfocus.com/bid/25428
Patch
http://www.sophos.com/support/knowledgebase/article/28407.html
Patch
http://www.vupen.com/english/advisories/2007/2972
http://securityreason.com/securityalert/3072
http://www.nruns.com/security_advisory_sophos_upx_infinite_loop_dos.php
http://www.securityfocus.com/archive/1/477720/100/0/threaded
http://www.securityfocus.com/archive/1/477864/100/0/threaded
http://www.securityfocus.com/archive/1/477882/100/0/threaded