CVE-2008-7104: Medium severity sophos puremessage anti-virus vulnerability
Sophos PureMessage Scanner service (PMScanner.exe) in PureMessage for Microsoft Exchange 3.0 before 3.0.2 allows remote attackers to cause a denial of service (message queue delay and incomplete spam rule update) via a crafted (1) RTF or (2) PDF file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7104?
CVE-2008-7104 is considered a moderate severity vulnerability due to its potential to cause service disruption.
How do I fix CVE-2008-7104?
To mitigate CVE-2008-7104, it is recommended to upgrade to PureMessage for Microsoft Exchange version 3.0.2 or later.
What are the effects of exploiting CVE-2008-7104?
Exploiting CVE-2008-7104 can lead to denial of service, causing message queue delays and incomplete updates to spam rules.
Which software is affected by CVE-2008-7104?
CVE-2008-7104 specifically affects Sophos PureMessage for Microsoft Exchange version 3.0.
Can CVE-2008-7104 be exploited remotely?
Yes, CVE-2008-7104 can be exploited remotely by sending crafted RTF or PDF files to the affected service.