{ "id": "CVE-2005-2768", "sourceIdentifier": "cve@mitre.org", "published": "2005-09-02T23:03:00.000", "lastModified": "2024-11-21T00:00:23.320", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Heap-based buffer overflow in the Sophos Antivirus Library, as used by Sophos Antivirus, PureMessage, MailMonitor, and other products, allows remote attackers to execute arbitrary code via a Visio file with a crafted sub record length." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "baseScore": 7.5, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL" }, "baseSeverity": "HIGH", "exploitabilityScore": 10.0, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": true, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:sophos:sophos_anti-virus:3.4.6:*:*:*:*:*:*:*", "matchCriteriaId": "22A1739A-B77D-4CD6-9943-52B336EC2F22" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sophos:sophos_anti-virus:3.78:*:*:*:*:*:*:*", "matchCriteriaId": "40D4EB83-A8A4-48F2-A835-FA192ADB3BFD" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sophos:sophos_anti-virus:3.78d:*:*:*:*:*:*:*", "matchCriteriaId": "1609D51F-41D1-441C-9EA8-3F0510D8ED8D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sophos:sophos_anti-virus:3.79:*:*:*:*:*:*:*", "matchCriteriaId": "3ABBFB36-0A7C-45ED-9907-867F31884113" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sophos:sophos_anti-virus:3.80:*:*:*:*:*:*:*", "matchCriteriaId": "23543D87-E4B6-4B74-A490-378D45AA3481" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sophos:sophos_anti-virus:3.81:*:*:*:*:*:*:*", "matchCriteriaId": "E4DBC8E3-0344-413A-8C4A-F48CBAAFAB91" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sophos:sophos_anti-virus:3.82:*:*:*:*:*:*:*", "matchCriteriaId": "28C3AD19-26F4-4AFF-8207-86017509EECC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sophos:sophos_anti-virus:3.83:*:*:*:*:*:*:*", "matchCriteriaId": "8EFC7217-88A6-4241-8FD9-4B7E2683F696" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sophos:sophos_anti-virus:3.84:*:*:*:*:*:*:*", "matchCriteriaId": "FDC8C9FC-9D35-455D-9597-3B2E63845B10" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sophos:sophos_anti-virus:3.85:*:*:*:*:*:*:*", "matchCriteriaId": "E07255F9-5726-4FDB-81A3-D0D55AD1F709" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sophos:sophos_anti-virus:3.86:*:*:*:*:*:*:*", "matchCriteriaId": "DD1A8D69-0A33-4F47-B1BA-8BC898A3E7EF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sophos:sophos_anti-virus:3.90:*:*:*:*:*:*:*", "matchCriteriaId": "06164FCF-CC47-406D-8561-DDA797B29673" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sophos:sophos_anti-virus:3.91:*:*:*:*:*:*:*", "matchCriteriaId": "A323A588-59DD-4D89-A224-A6FF7BBD7B37" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sophos:sophos_anti-virus:3.95:*:*:*:*:*:*:*", "matchCriteriaId": "B7CDEAF9-0769-4570-8191-DA368938FDFE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sophos:sophos_anti-virus:4.5.3:*:*:*:*:*:*:*", "matchCriteriaId": "7B0A4880-4C6D-45F4-A9E3-45F89565A70E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sophos:sophos_anti-virus:5.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "0756438F-DD69-4213-9069-FA613A5D729E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sophos:sophos_anti-virus:5.0.4:*:*:*:*:*:*:*", "matchCriteriaId": "F0FB0CD9-91CB-43C5-9CB5-1B3BC665D134" } ] } ] } ], "references": [ { "url": "http://marc.info/?l=bugtraq&m=112511873420953&w=2", "source": "cve@mitre.org" }, { "url": "http://secunia.com/advisories/16245/", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.rem0te.com/public/images/sophos.pdf", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.securityfocus.com/bid/14362", "source": "cve@mitre.org" }, { "url": "http://www.sophos.com/support/knowledgebase/article/3409.html", "source": "cve@mitre.org" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/21608", "source": "cve@mitre.org" }, { "url": "http://marc.info/?l=bugtraq&m=112511873420953&w=2", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://secunia.com/advisories/16245/", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.rem0te.com/public/images/sophos.pdf", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.securityfocus.com/bid/14362", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.sophos.com/support/knowledgebase/article/3409.html", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/21608", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }