First published: Thu Aug 27 2009(Updated: )
The installation of Sophos PureMessage for Microsoft Exchange 3.0 before 3.0.2, when both anti-virus and anti-spam are supported, does not create or launch the associated scan engines when the system is under heavy load, which has unspecified impact, probably remote bypass of scanner protection or a denial of service (message loss or delay).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos PureMessage Anti-virus | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-7106 has a moderate severity level due to potential remote bypass of scanner protection.
To fix CVE-2008-7106, upgrade to Sophos PureMessage for Microsoft Exchange version 3.0.2 or later.
CVE-2008-7106 affects Sophos PureMessage for Microsoft Exchange version 3.0 prior to 3.0.2.
CVE-2008-7106 can potentially lead to a remote bypass of scanner protection when the system is under heavy load.
There is no specified workaround for CVE-2008-7106; upgrading to the fixed version is recommended.