Vulnerabilities > CVE-2007-0125 - Denial Of Service vulnerability in Kaspersky LAB Kaspersky Antivirus Engine 5.5.10/6.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
PARTIAL Summary
Kaspersky Labs Antivirus Engine 6.0 for Windows and 5.5-10 for Linux before 20070102 enter an infinite loop upon encountering an invalid NumberOfRvaAndSizes value in the Optional Windows Header of a portable executable (PE) file, which allows remote attackers to cause a denial of service (CPU consumption) by scanning a crafted PE file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Nessus
NASL family | Windows |
NASL id | KASPERSKY_PE_DOS.NASL |
description | The version of Kaspersky Anti-Virus installed on the remote host is affected by a denial of service issue that can be triggered with a specially crafted PE (portable executable) file to send the scanning engine into an infinite loop and prevent scanning of other files. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 23997 |
published | 2007-01-09 |
reporter | This script is Copyright (C) 2007-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/23997 |
title | Kaspersky Anti-Virus PE File Handling DoS |
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=459
- http://osvdb.org/32588
- http://secunia.com/advisories/23575
- http://securitytracker.com/id?1017476
- http://www.securityfocus.com/bid/21901
- http://www.vupen.com/english/advisories/2007/0067
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31315