CVE-2004-2075: Medium severity Sophos Anti-Virus vulnerability
Published Dec 31, 2004
·Updated
Sophos Anti-Virus 3.78 allows remote attackers to cause a denial of service (infinite loop) via a MIME header that is not properly terminated.
Affected Software
4 affected components
Sophos Anti-Virus=3.46
Sophos Anti-Virus=3.78
Sophos Anti-Virus=3.46
Sophos Anti-Virus=3.78
Remediation
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
May 19, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2075?
CVE-2004-2075 is classified as a denial of service vulnerability due to the infinite loop caused by improperly terminated MIME headers.
2
How do I fix CVE-2004-2075?
To address CVE-2004-2075, upgrade to a patched version of Sophos Anti-Virus that resolves this issue.
3
Which versions of Sophos Anti-Virus are affected by CVE-2004-2075?
CVE-2004-2075 affects Sophos Anti-Virus versions 3.46 and 3.78.
4
What impact does CVE-2004-2075 have on affected systems?
CVE-2004-2075 can cause a denial of service by making the affected Sophos Anti-Virus software enter an infinite loop.
5
Is there a workaround for CVE-2004-2075 if I cannot immediately update?
There are no known workarounds for CVE-2004-2075, so applying the appropriate update is essential.