Vulnerability Name: | CVE-2007-2972 (CCN-34556) | ||||||||
Assigned: | 2007-05-29 | ||||||||
Published: | 2007-05-29 | ||||||||
Updated: | 2018-10-16 | ||||||||
Summary: | The file parsing engine in Avira Antivir Antivirus before 7.04.00.24 allows remote attackers to cause a denial of service (application crash) via a crafted UPX compressed file, which triggers a divide-by-zero error. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
| ||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C) 5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Mon May 28 2007 - 22:07:27 CDT n.runs-SA-2007.011 - Avira Antivir Antivirus UPX parsing Divide by Zero Advisory Source: MITRE Type: CNA CVE-2007-2972 Source: CONFIRM Type: Patch http://forum.antivir-pe.de/thread.php?threadid=22528 Source: FULLDISC Type: UNKNOWN 20070529 n.runs-SA-2007.011 - Avira Antivir Antivirus UPX Source: OSVDB Type: UNKNOWN 36710 Source: CCN Type: SA25417 Avira Antivir Multiple File Processing Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 25417 Source: CCN Type: SECTRACK ID: 1018132 AntiVir Divide By Zero Error in Processing UPX Packed Files Lets Remote Users Deny Service Source: CCN Type: Avira Web site Avira Products Source: MISC Type: Vendor Advisory http://www.nruns.com/advisories/%5Bn.runs-SA-2007.011%5D%20-%20Avira%20Antivir%20Antivirus%20UPX%20parsing%20Divide%20by%20Zero%20Advisory.txt Source: CCN Type: OSVDB ID: 36710 Avira AntiVir Antivirus UPX File Handling DoS Source: BUGTRAQ Type: UNKNOWN 20070529 n.runs-SA-2007.011 - Avira Antivir Antivirus UPX parsing Divide by Zero Advisory Source: BID Type: Patch 24187 Source: CCN Type: BID-24187 Avira Antivir Antivirus Multiple Remote Vulnerabilities Source: SECTRACK Type: UNKNOWN 1018132 Source: VUPEN Type: UNKNOWN ADV-2007-1971 Source: XF Type: UNKNOWN avira-antivir-upx-dos(34556) Source: XF Type: UNKNOWN avira-antivir-upx-dos(34556) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |