zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
Link | Tags |
---|---|
http://www.amavis.org/security/asa-2007-2.txt | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34080 | vdb entry |
http://www.vupen.com/english/advisories/2007/1699 | vdb entry |
http://www.securityfocus.com/bid/23823 | vdb entry exploit |
http://www.attrition.org/pipermail/vim/2007-July/001725.html | mailing list |
http://secunia.com/advisories/25315 | third party advisory vendor advisory |
http://www.securityfocus.com/archive/1/467646/100/0/threaded | mailing list |
http://secunia.com/advisories/25122 | patch vendor advisory third party advisory |
http://securityreason.com/securityalert/2680 | third party advisory |
http://www.osvdb.org/35795 | vdb entry |