Vulnerabilities > CVE-2007-1281 - Unspecified vulnerability in Kaspersky LAB Kaspersky Antivirus Engine 5.5.10/6.0.1.411
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN kaspersky-lab
nessus
Summary
Kaspersky AntiVirus Engine 6.0.1.411 for Windows and 5.5-10 for Linux allows remote attackers to cause a denial of service (CPU consumption) via a crafted UPX compressed file with a negative offset, which triggers an infinite loop during decompression.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 1 | |
OS | 1 | |
Application | 2 |
Nessus
NASL family | Windows |
NASL id | KASPERSKY_UPX_DECOMPRESSION_DOS.NASL |
description | The version of Kaspersky Anti-Virus installed on the remote host reportedly may enter an infinite loop when it attempts to process an executable with specially crafted compressed UPX data. A remote attacker may be able to exploit this issue to cause the affected host to consume all available CPU cycles, thereby denying service to users of the affected host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 24758 |
published | 2007-03-05 |
reporter | This script is Copyright (C) 2007-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/24758 |
title | Kaspersky Anti-Virus UPX File Decompression DoS |
code |
|
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=485
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=485
- http://secunia.com/advisories/24391
- http://secunia.com/advisories/24391
- http://www.securityfocus.com/bid/22795
- http://www.securityfocus.com/bid/22795
- http://www.securitytracker.com/id?1017718
- http://www.securitytracker.com/id?1017718
- http://www.vupen.com/english/advisories/2007/0810
- http://www.vupen.com/english/advisories/2007/0810
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32797
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32797