CVE-2007-3875: Medium severity Broadcom Anti-spyware vulnerability

Published Jul 26, 2007
·
Updated

arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" field in a CHM file.

Affected Software

41 affected components
Broadcom Anti-spyware=2007
Broadcom Anti-virus For The Enterprise<=8
Broadcom Anti-virus For The Enterprise=7.0
Broadcom Anti-virus For The Enterprise=7.1
Broadcom Anti-virus For The Enterprise=8
Broadcom Anti-virus For The Enterprise=8.1
Broadcom Anti Virus Sdk
Broadcom Antispyware For The Enterprise=8
Broadcom Antispyware For The Enterprise=8.1
Broadcom Antivirus Sdk
Broadcom Brightstor Arcserve Backup=9.01
Broadcom Brightstor Arcserve Backup=11.1
Broadcom Brightstor Arcserve Backup=11.5
Broadcom Brightstor Arcserve Client
Broadcom Brightstor Enterprise Backup=10.5
Broadcom Brigthstor Arcserve Client For Windows
Broadcom Common Services=11
Broadcom Common Services=11.1
Broadcom Etrust Antivirus=8
Broadcom Etrust Antivirus Gateway=7.1
Broadcom Etrust Ez Antivirus=6.1
Broadcom Etrust Ez Antivirus=7
Broadcom Etrust Ez Armor=1
Broadcom Etrust Ez Armor=2
Broadcom Etrust Ez Armor=3
Broadcom Etrust Internet Security Suite=1
Broadcom Etrust Internet Security Suite=2
Broadcom Etrust Intrusion Detection=2.0
Broadcom Etrust Intrusion Detection=3.0
Broadcom Internet Security Suite=3.0
Broadcom Secure Content Manager=1.1
Broadcom Secure Content Manager=8.0
Broadcom Threat Manager=8
Broadcom Unicenter Network And Systems Management=3.0
Broadcom Unicenter Network And Systems Management=3.1
Broadcom Unicenter Network And Systems Management=11
Broadcom Unicenter Network And Systems Management=11.1
CA BrightStor ARCserve Backup=11
CA eTrust Intrusion Detection=3.0-sp1
CA Protection Suites=r2
CA Protection Suites=r3

Event History

Jul 26, 2007
CVE Published
12:30 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2007-3875?

CVE-2007-3875 is classified as a denial of service vulnerability that can significantly disrupt antivirus functionality.

2

How do I fix CVE-2007-3875?

To mitigate CVE-2007-3875, update the affected CA Anti-Virus products to versions 7.3.0.9 or later.

3

Which products are affected by CVE-2007-3875?

CVE-2007-3875 affects CA Anti-Virus products prior to version 7.3.0.9 including various versions of eTrust Antivirus and Anti-Spyware.

4

What type of attack does CVE-2007-3875 involve?

CVE-2007-3875 involves an attack that leads to an infinite loop within the antivirus software when processing an invalid CHM file.

5

Is CVE-2007-3875 exploitability easy?

CVE-2007-3875 can be exploited remotely, making it a relatively easy target for attackers if the antivirus software is not updated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203