First published: Wed May 09 2007(Updated: )
zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Barracuda Spam Firewall | =3.1.17 | |
Barracuda Spam Firewall | =3.1.18 | |
Barracuda Spam Firewall | =3.3.0.54 | |
Barracuda Spam Firewall | =3.3.01.001 | |
Barracuda Spam Firewall | =3.3.3 | |
Barracuda Spam Firewall | =3.3.03.053 | |
Barracuda Spam Firewall | =3.3.03.055 | |
Barracuda Spam Firewall | =3.3.15.026 | |
Barracuda Spam Firewall | =3.4 | |
AMaViS | <=2.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1669 has a low severity rating and is primarily associated with denial of service vulnerabilities.
To fix CVE-2007-1669, upgrade to the latest version of the affected software or apply the available patches.
CVE-2007-1669 affects Barracuda Spam Firewall versions before 3.4 and AMaViS versions up to 2.4.1.
Yes, CVE-2007-1669 can be exploited remotely by attackers to induce a denial of service.
The exploitation of CVE-2007-1669 may lead to service outages or degraded performance in the affected applications.