First published: Tue Jul 19 2005(Updated: )
Sophos Anti-Virus 5.0.1, with "Scan inside archive files" enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large 'Extra field length' value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Small Business Suite | =1.0 | |
Sophos Anti-Virus | =3.83 | |
Sophos Anti-Virus | =3.91 | |
Sophos MailMonitor | ||
Sophos MailMonitor | =2.1 | |
Sophos Anti-Virus | =3.80 | |
Sophos Anti-Virus | =3.81 | |
Sophos Anti-Virus | =3.86 | |
Sophos Anti-Virus | =3.78 | |
Sophos Anti-Virus | =3.82 | |
Sophos Anti-Virus | =3.79 | |
Sophos PureMessage Anti-virus | =4.6 | |
Sophos Anti-Virus | =3.78d | |
Sophos Anti-Virus | =3.90 | |
Sophos Anti-Virus | =3.4.6 | |
Sophos Anti-Virus | =5.0.1 | |
Sophos Anti-Virus | =3.84 | |
Sophos MailMonitor | =2.0 | |
Sophos Anti-Virus | =3.85 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1530 is classified as a denial of service vulnerability due to high CPU consumption.
To mitigate CVE-2005-1530, disable the "Scan inside archive files" feature in Sophos Anti-Virus settings.
CVE-2005-1530 affects Sophos Anti-Virus versions 5.0.1 and earlier, as well as specific versions of Sophos MailMonitor.
Yes, CVE-2005-1530 can be exploited remotely by sending a specially crafted Bzip2 archive.
CVE-2005-1530 can lead to system unresponsiveness and resource exhaustion, affecting availability.