First published: Tue Jul 15 2008(Updated: )
Sophos virus detection engine 2.75 on Linux and Unix, as used in Sophos Email Appliance, Pure Message for Unix, and Sophos Anti-Virus Interface (SAVI), allows remote attackers to cause a denial of service (engine crash) via zero-length MIME attachments.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Email Appliance | =es1000 | |
Sophos Email Appliance | =es4000 | |
Sophos ES1000 | ||
Sophos ES4000 | ||
Sophos Anti-Virus | ||
Sophos PureMessage Anti-virus |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3177 is classified as a denial of service vulnerability that can cause the Sophos virus detection engine to crash.
To fix CVE-2008-3177, you should upgrade to a patched version of the Sophos antivirus software that addresses this vulnerability.
CVE-2008-3177 affects Sophos Email Appliance, Sophos ES1000, Sophos ES4000, Sophos Anti-Virus, and Sophos PureMessage Anti-virus.
CVE-2008-3177 can be exploited by remote attackers through the sending of zero-length MIME attachments.
The impact of CVE-2008-3177 is a denial of service that can lead to a system crash, thereby affecting service availability.