CVE-2007-1281: High severity Microsoft All Windows vulnerability
Kaspersky AntiVirus Engine 6.0.1.411 for Windows and 5.5-10 for Linux allows remote attackers to cause a denial of service (CPU consumption) via a crafted UPX compressed file with a negative offset, which triggers an infinite loop during decompression.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1281?
CVE-2007-1281 has a high severity rating due to its potential to cause denial of service through CPU consumption.
How do I fix CVE-2007-1281?
To mitigate CVE-2007-1281, update to a fixed version of Kaspersky AntiVirus Engine that addresses this vulnerability.
Which versions of Kaspersky are affected by CVE-2007-1281?
CVE-2007-1281 affects Kaspersky AntiVirus Engine versions 6.0.1.411 and 5.5-10.
What is the impact of CVE-2007-1281?
The impact of CVE-2007-1281 is a denial of service that results from an infinite loop during the decompression of a crafted UPX file.
Can CVE-2007-1281 be exploited remotely?
Yes, CVE-2007-1281 can be exploited remotely, allowing attackers to trigger the denial of service condition.