CVE-2005-1530: Medium severity Sophos Sophos Small Business Suite vulnerability
Published Jul 19, 2005
·Updated
Sophos Anti-Virus 5.0.1, with "Scan inside archive files" enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large 'Extra field length' value.
Affected Software
19 affected components
Sophos Sophos Small Business Suite=1.0
Sophos Sophos Anti-Virus=3.83
Sophos Sophos Anti-Virus=3.91
Sophos Sophos Mailmonitor For Notes Domino
Sophos Sophos Mailmonitor=2.1
Sophos Sophos Anti-Virus=3.80
Sophos Sophos Anti-Virus=3.81
Sophos Sophos Anti-Virus=3.86
Sophos Sophos Anti-Virus=3.78
Sophos Sophos Anti-Virus=3.82
Sophos Sophos Anti-Virus=3.79
Sophos Sophos Puremessage Anti-virus=4.6
Sophos Sophos Anti-Virus=3.78d
Sophos Sophos Anti-Virus=3.90
Sophos Sophos Anti-Virus=3.4.6
Sophos Sophos Anti-Virus=5.0.1
Sophos Sophos Anti-Virus=3.84
Sophos Sophos Mailmonitor=2.0
Sophos Sophos Anti-Virus=3.85
Remediation
Patch Available
Event History
Jul 19, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1530?
CVE-2005-1530 is classified as a denial of service vulnerability due to high CPU consumption.
2
How do I fix CVE-2005-1530?
To mitigate CVE-2005-1530, disable the "Scan inside archive files" feature in Sophos Anti-Virus settings.
3
Which versions are affected by CVE-2005-1530?
CVE-2005-1530 affects Sophos Anti-Virus versions 5.0.1 and earlier, as well as specific versions of Sophos MailMonitor.
4
Can CVE-2005-1530 be exploited remotely?
Yes, CVE-2005-1530 can be exploited remotely by sending a specially crafted Bzip2 archive.
5
What impact does CVE-2005-1530 have on systems?
CVE-2005-1530 can lead to system unresponsiveness and resource exhaustion, affecting availability.