First published: Thu Aug 27 2009(Updated: )
Sophos PureMessage Scanner service (PMScanner.exe) in PureMessage for Microsoft Exchange 3.0 before 3.0.2 allows remote attackers to cause a denial of service (message queue delay and incomplete spam rule update) via a crafted (1) RTF or (2) PDF file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos PureMessage Anti-virus | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-7104 is considered a moderate severity vulnerability due to its potential to cause service disruption.
To mitigate CVE-2008-7104, it is recommended to upgrade to PureMessage for Microsoft Exchange version 3.0.2 or later.
Exploiting CVE-2008-7104 can lead to denial of service, causing message queue delays and incomplete updates to spam rules.
CVE-2008-7104 specifically affects Sophos PureMessage for Microsoft Exchange version 3.0.
Yes, CVE-2008-7104 can be exploited remotely by sending crafted RTF or PDF files to the affected service.