CVE-2008-5425: Medium severity ESET NOD32 Antivirus vulnerability
ESet NOD32 2.70.0039.0000 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (stack consumption or other resource consumption) via a large e-mail message, a related issue to CVE-2006-1173.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5425?
CVE-2008-5425 has been classified as a denial of service vulnerability that can lead to resource exhaustion.
How do I fix CVE-2008-5425?
To mitigate CVE-2008-5425, users should upgrade to a newer version of ESET NOD32 Antivirus that is not affected by this vulnerability.
What are the consequences of CVE-2008-5425?
Exploiting CVE-2008-5425 allows remote attackers to cause stack consumption leading to denial of service.
Which versions of ESET NOD32 Antivirus are affected by CVE-2008-5425?
ESET NOD32 Antivirus version 2.70.0039.0000 is specifically affected by CVE-2008-5425.
What types of messages can trigger CVE-2008-5425?
CVE-2008-5425 can be triggered by multipart/mixed e-mail messages with numerous MIME parts or by messages containing many 'Content-type: message/rfc822;' headers.