CVE-2007-4577: High severity SOPHOS Anti-Virus vulnerability
Sophos Anti-Virus for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed BZip file that results in the creation of multiple Engine temporary files (aka a "BZip bomb").
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4577?
CVE-2007-4577 is classified as a denial of service vulnerability due to the potential for an infinite loop caused by a malformed BZip file.
How do I fix CVE-2007-4577?
To mitigate CVE-2007-4577, it is recommended to upgrade to Sophos Anti-Virus version 2.48.0 or later.
What are the affected versions of Sophos Anti-Virus for CVE-2007-4577?
Affected versions for CVE-2007-4577 include Sophos Anti-Virus versions prior to 2.48.0, specifically versions 3.4.6 through 6.5.
What is a BZip bomb in relation to CVE-2007-4577?
A BZip bomb is a malicious file designed to exploit the vulnerability in CVE-2007-4577 by causing the software to enter an infinite loop and consume resources.
Can CVE-2007-4577 be exploited remotely?
Yes, CVE-2007-4577 can be exploited remotely by attackers through the use of a specially crafted BZip file.