Vulnerabilities > CVE-2007-0125 - Denial Of Service vulnerability in Kaspersky LAB Kaspersky Antivirus Engine 5.5.10/6.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
kaspersky-lab
nessus

Summary

Kaspersky Labs Antivirus Engine 6.0 for Windows and 5.5-10 for Linux before 20070102 enter an infinite loop upon encountering an invalid NumberOfRvaAndSizes value in the Optional Windows Header of a portable executable (PE) file, which allows remote attackers to cause a denial of service (CPU consumption) by scanning a crafted PE file.

Nessus

NASL familyWindows
NASL idKASPERSKY_PE_DOS.NASL
descriptionThe version of Kaspersky Anti-Virus installed on the remote host is affected by a denial of service issue that can be triggered with a specially crafted PE (portable executable) file to send the scanning engine into an infinite loop and prevent scanning of other files.
last seen2020-06-01
modified2020-06-02
plugin id23997
published2007-01-09
reporterThis script is Copyright (C) 2007-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/23997
titleKaspersky Anti-Virus PE File Handling DoS