Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:14855
HistoryOct 30, 2006 - 12:00 a.m.

[SA22635] Sophos Anti-Virus Petite Plugin Denial of Service Vulnerability

2006-10-3000:00:00
vulners.com
11

TITLE:
Sophos Anti-Virus Petite Plugin Denial of Service Vulnerability

SECUNIA ADVISORY ID:
SA22635

VERIFY ADVISORY:
http://secunia.com/advisories/22635/

CRITICAL:
Moderately critical

IMPACT:
DoS

WHERE:
>From remote

SOFTWARE:
Sophos Anti-Virus for Windows 6.x
http://secunia.com/product/12449/
Sophos Anti-Virus 5.x
http://secunia.com/product/5390/
Sophos Anti-Virus 4.x
http://secunia.com/product/5391/
Sophos Anti-Virus Small Business Edition
http://secunia.com/product/9822/

DESCRIPTION:
A vulnerability has been reported in Sophos Anti-Virus, which can be
exploited by malicious people to cause a DoS (Denial of Service).

An unspecified error in the Petite plugin when processing Petite
archives containing a large number of large sectors can be exploited
to DoS the virus engine.

Please see the vendor's advisory for a list of affected versions.

SOLUTION:
Updates are available for all products, but Sophos Anti-Virus for
Macintosh (available in December 2006).

PROVIDED AND/OR DISCOVERED BY:
The vendor credits iDefense.

ORIGINAL ADVISORY:
Sophos:
http://www.sophos.com/support/knowledgebase/article/7609.html


About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.