SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-3875

arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk…

MEDIUM 4.3EPSS 3.54%

Does this matter?

Lower severity and a low EPSS score (3.54%). Track it; it rarely justifies an emergency change on its own.

Description

arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" field in a CHM file.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
EPSS
3.54% probability · 89th percentile
CISA KEV
Not listed
Affected
broadcom/anti-spyware · broadcom/anti-virus for the enterprise · broadcom/anti virus sdk · broadcom/antispyware for the enterprise · broadcom/antivirus sdk · broadcom/brightstor arcserve backup · broadcom/brightstor arcserve client · broadcom/brightstor enterprise backup · broadcom/brigthstor arcserve client for windows · broadcom/common services · broadcom/etrust antivirus · broadcom/etrust antivirus gateway · broadcom/etrust ez antivirus · broadcom/etrust ez armor · broadcom/etrust internet security suite · broadcom/etrust intrusion detection · broadcom/internet security suite · broadcom/secure content manager · broadcom/threat manager · broadcom/unicenter network and systems management · +3 more
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.