Vulnerability Name:

CVE-2005-2768 (CCN-21608)

Assigned:2005-07-27
Published:2005-07-27
Updated:2017-07-11
Summary:Heap-based buffer overflow in the Sophos Antivirus Library, as used by Sophos Antivirus, PureMessage, MailMonitor, and other products, allows remote attackers to execute arbitrary code via a Visio file with a crafted sub record length.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: Full-Disclosure Mailing List, Fri Aug 26 2005 - 07:36:01 CDT
Sophos Antivirus Library Remote Heap Overflow

Source: MITRE
Type: CNA
CVE-2005-2768

Source: BUGTRAQ
Type: UNKNOWN
20050826 Sophos Antivirus Library Remote Heap Overflow

Source: CCN
Type: SA16245
Sophos Anti-Virus Visio File Parsing Buffer Overflow

Source: SECUNIA
Type: Vendor Advisory
16245

Source: CCN
Type: OSVDB ID: 18464
Sophos Anti-Virus Visio File Processing Overflow

Source: MISC
Type: Vendor Advisory
http://www.rem0te.com/public/images/sophos.pdf

Source: BID
Type: UNKNOWN
14362

Source: CCN
Type: BID-14362
Sophos Anti-Virus Library Visio Scanning Remote Heap Overflow Vulnerability

Source: CCN
Type: Sophos Web site
Sophos Anti-Virus

Source: CCN
Type: Sophos Technical Advisory
Sophos buffer overflow vulnerability

Source: CONFIRM
Type: UNKNOWN
http://www.sophos.com/support/knowledgebase/article/3409.html

Source: XF
Type: UNKNOWN
sophos-bo(21608)

Source: XF
Type: UNKNOWN
sophos-bo(21608)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sophos:sophos_anti-virus:3.4.6:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:sophos_anti-virus:3.78:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:sophos_anti-virus:3.78d:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:sophos_anti-virus:3.79:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:sophos_anti-virus:3.80:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:sophos_anti-virus:3.81:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:sophos_anti-virus:3.82:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:sophos_anti-virus:3.83:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:sophos_anti-virus:3.84:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:sophos_anti-virus:3.85:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:sophos_anti-virus:3.86:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:sophos_anti-virus:3.90:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:sophos_anti-virus:3.91:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:sophos_anti-virus:3.95:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:sophos_anti-virus:4.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:sophos_anti-virus:5.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:sophos:sophos_anti-virus:5.0.4:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sophos sophos anti-virus 3.4.6
    sophos sophos anti-virus 3.78
    sophos sophos anti-virus 3.78d
    sophos sophos anti-virus 3.79
    sophos sophos anti-virus 3.80
    sophos sophos anti-virus 3.81
    sophos sophos anti-virus 3.82
    sophos sophos anti-virus 3.83
    sophos sophos anti-virus 3.84
    sophos sophos anti-virus 3.85
    sophos sophos anti-virus 3.86
    sophos sophos anti-virus 3.90
    sophos sophos anti-virus 3.91
    sophos sophos anti-virus 3.95
    sophos sophos anti-virus 4.5.3
    sophos sophos anti-virus 5.0.1
    sophos sophos anti-virus 5.0.4