René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

159 lines
5.7 KiB
JSON

{
"id": "CVE-2007-1669",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-05-09T00:19:00.000",
"lastModified": "2018-10-16T16:40:20.380",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file."
},
{
"lang": "es",
"value": "zoo decoder versi\u00f3n 2.10 (zoo-2.10), tal como se utiliza en m\u00faltiples productos, incluyendo (1) Barracuda Spam Firewall versi\u00f3n 3.4 y posterior con virusdef anterior a la versi\u00f3n 2.0.6399, (2) Spam Firewall anterior a la versi\u00f3n 3.4 20070319 con virusdef anterior a 2.0.6399o, y (3) AmaViS versi\u00f3n 2.4.1 y anteriores, permite a atacantes remotos generar una denegaci\u00f3n de servicio (bucle infinito) por medio del componente ZOO Archive con una estructura direntry que apunta hacia un archivo anterior."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "COMPLETE",
"baseScore": 7.8
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:barracuda_networks:barracuda_spam_firewall:3.1.17:*:*:*:*:*:*:*",
"matchCriteriaId": "7A9DC6C5-D228-43AC-8ED1-5A7E5315E275"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:barracuda_networks:barracuda_spam_firewall:3.1.18:*:*:*:*:*:*:*",
"matchCriteriaId": "47F9E0B8-8BCF-4259-A415-909FD349DB2A"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:barracuda_networks:barracuda_spam_firewall:3.3.0.54:*:*:*:*:*:*:*",
"matchCriteriaId": "159185A2-272C-46EC-A96A-84FB80B6473E"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:barracuda_networks:barracuda_spam_firewall:3.3.01.001:*:*:*:*:*:*:*",
"matchCriteriaId": "4499AB68-D449-4A36-A243-F13F02C0EF95"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:barracuda_networks:barracuda_spam_firewall:3.3.3:*:*:*:*:*:*:*",
"matchCriteriaId": "5BC3E5FA-1A08-4D4C-865E-547D50E21349"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:barracuda_networks:barracuda_spam_firewall:3.3.03.053:*:*:*:*:*:*:*",
"matchCriteriaId": "E9E13260-BC29-45D9-98F3-0C2D7CF72A42"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:barracuda_networks:barracuda_spam_firewall:3.3.03.055:*:*:*:*:*:*:*",
"matchCriteriaId": "3DB02038-4858-4D43-9FB6-492E131227CA"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:barracuda_networks:barracuda_spam_firewall:3.3.15.026:*:*:*:*:*:*:*",
"matchCriteriaId": "FAA3E09E-6F3C-4ED9-AD6C-3F8938A629B2"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:barracuda_networks:barracuda_spam_firewall:3.4:*:*:*:*:*:*:*",
"matchCriteriaId": "E5A431D3-D4D1-43F0-9D2F-C3D0CB58EA36"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:amavis:amavis:*:*:*:*:*:*:*:*",
"versionEndIncluding": "2.4.1",
"matchCriteriaId": "64AF6FAE-B025-4F70-9F52-C7C12C6F705D"
}
]
}
]
}
],
"references": [
{
"url": "http://securityreason.com/securityalert/2680",
"source": "cve@mitre.org"
},
{
"url": "http://www.amavis.org/security/asa-2007-2.txt",
"source": "cve@mitre.org"
},
{
"url": "http://www.attrition.org/pipermail/vim/2007-July/001725.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/467646/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/23823",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://www.vupen.com/english/advisories/2007/1699",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34080",
"source": "cve@mitre.org"
}
]
}