CVE-2005-2768: Buffer Overflow
Published Sep 2, 2005
·Updated
Heap-based buffer overflow in the Sophos Antivirus Library, as used by Sophos Antivirus, PureMessage, MailMonitor, and other products, allows remote attackers to execute arbitrary code via a Visio file with a crafted sub record length.
Affected Software
17 affected components
Sophos Anti-Virus=3.4.6
Sophos Anti-Virus=3.78
Sophos Anti-Virus=3.78d
Sophos Anti-Virus=3.79
Sophos Anti-Virus=3.80
Sophos Anti-Virus=3.81
Sophos Anti-Virus=3.82
Sophos Anti-Virus=3.83
Sophos Anti-Virus=3.84
Sophos Anti-Virus=3.85
Sophos Anti-Virus=3.86
Sophos Anti-Virus=3.90
Sophos Anti-Virus=3.91
Sophos Anti-Virus=3.95
Sophos Anti-Virus=4.5.3
Sophos Anti-Virus=5.0.1
Sophos Anti-Virus=5.0.4
Event History
Sep 2, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2768?
CVE-2005-2768 has a high severity due to its potential to allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2005-2768?
To fix CVE-2005-2768, update the affected Sophos Antivirus software to the latest version provided by Sophos.
3
Which products are affected by CVE-2005-2768?
CVE-2005-2768 affects Sophos Antivirus, PureMessage, MailMonitor, and other products that use the Sophos Antivirus Library.
4
What type of vulnerability is CVE-2005-2768?
CVE-2005-2768 is a heap-based buffer overflow vulnerability.
5
How can attackers exploit CVE-2005-2768?
Attackers can exploit CVE-2005-2768 by sending a specially crafted Visio file that triggers the buffer overflow.