CVE-2003-1444: Input Validation
Published Dec 31, 2003
·Updated
Kaspersky Antivirus (KAV) 4.0.9.0 allows local users to cause a denial of service (CPU consumption or crash) and prevent malicious code from being detected via a file with a long pathname.
Affected Software
1 affected component
Kaspersky Lab Kaspersky Anti-virus=4.0.9.0
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Oct 23, 2007
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1444?
The severity of CVE-2003-1444 is high, as it allows local users to cause a denial of service.
2
How do I fix CVE-2003-1444?
To mitigate CVE-2003-1444, it is recommended to upgrade to a fixed version of Kaspersky Anti-Virus beyond 4.0.9.0.
3
What type of attack does CVE-2003-1444 enable?
CVE-2003-1444 enables a denial of service attack by exploiting long pathnames to consume CPU resources.
4
Who is affected by CVE-2003-1444?
CVE-2003-1444 specifically affects users of Kaspersky Anti-Virus version 4.0.9.0.
5
What is the impact of CVE-2003-1444 on Kaspersky Antivirus?
The impact of CVE-2003-1444 on Kaspersky Antivirus includes potential system crashes and undetected malicious code.