VulnerabilityModified
CVE-2008-3177
Sophos virus detection engine 2.75 on Linux and Unix, as used in Sophos Email Appliance, Pure Message for Unix, and Sophos Anti-Virus Interface (SAVI), allows remote attackers to cause a denial of service (engine crash) via zero-length MIME attachments.
MEDIUM 5.0EPSS 5.13%
Does this matter?
Lower severity and a low EPSS score (5.13%). Track it; it rarely justifies an emergency change on its own.
Description
Sophos virus detection engine 2.75 on Linux and Unix, as used in Sophos Email Appliance, Pure Message for Unix, and Sophos Anti-Virus Interface (SAVI), allows remote attackers to cause a denial of service (engine crash) via zero-length MIME attachments.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 5.13% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-16
- Affected
- sophos/es1000 · sophos/es4000 · sophos/sophos anti-virus · sophos/sophos puremessage anti-virus
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/31037Vendor Advisory
- http://www.securityfocus.com/bid/30110
- http://www.securitytracker.com/id?1020462
- http://www.sophos.com/support/knowledgebase/article/42245.html?_log_from=rss
- http://www.vupen.com/english/advisories/2008/2053/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43703
- http://secunia.com/advisories/31037Vendor Advisory
- http://www.securityfocus.com/bid/30110
- http://www.securitytracker.com/id?1020462
- http://www.sophos.com/support/knowledgebase/article/42245.html?_log_from=rss
- http://www.vupen.com/english/advisories/2008/2053/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43703
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.