CVE-2007-3875: Medium severity Broadcom Anti-spyware vulnerability
arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" field in a CHM file.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3875?
CVE-2007-3875 is classified as a denial of service vulnerability that can significantly disrupt antivirus functionality.
How do I fix CVE-2007-3875?
To mitigate CVE-2007-3875, update the affected CA Anti-Virus products to versions 7.3.0.9 or later.
Which products are affected by CVE-2007-3875?
CVE-2007-3875 affects CA Anti-Virus products prior to version 7.3.0.9 including various versions of eTrust Antivirus and Anti-Spyware.
What type of attack does CVE-2007-3875 involve?
CVE-2007-3875 involves an attack that leads to an infinite loop within the antivirus software when processing an invalid CHM file.
Is CVE-2007-3875 exploitability easy?
CVE-2007-3875 can be exploited remotely, making it a relatively easy target for attackers if the antivirus software is not updated.