| Vulnerability Name: | CVE-2007-3972 (CCN-35524) | ||||||||
| Assigned: | 2007-07-20 | ||||||||
| Published: | 2007-07-20 | ||||||||
| Updated: | 2018-10-15 | ||||||||
| Summary: | ESET NOD32 Antivirus before 2.2289 allows remote attackers to cause a denial of service via a crafted (1) ASPACK or (2) FSG packed file, which triggers a divide-by-zero error. | ||||||||
| CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Denial of Service | ||||||||
| References: | Source: CCN Type: Full-Disclosure Mailing List, Fri Jul 20 2007 - 14:43:50 CDT n.runs-SA-2007.018 - NOD32 Antivirus ASPACK and FSG parsing Divide by Zero Advisory Source: MITRE Type: CNA CVE-2007-3972 Source: OSVDB Type: UNKNOWN 37978 Source: CCN Type: SA26124 NOD32 Antivirus Multiple File Processing Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 26124 Source: SREASON Type: UNKNOWN 2924 Source: CCN Type: Eset Web site 2289: Fixed problems in run-time decompressors Source: CONFIRM Type: Patch http://www.eset.com/joomla/index.php?option=com_content&task=view&id=3469&Itemid=26 Source: MISC Type: Broken Link http://www.nruns.com/[n.runs-SA-2007.018]%20-%20NOD32%20Antivirus%20ASPACK%20and%20FSG%20parsing%20Divide%20by%20Zero%20Advisory.pdf Source: MISC Type: Broken Link http://www.nruns.com/[n.runs-SA-2007.018]%20-%20NOD32%20Antivirus%20ASPACK%20and%20FSG%20parsing%20Divide%20by%20Zero%20Advisory.txt Source: CCN Type: OSVDB ID: 37978 NOD32 Antivirus Crafted ASPACK / FSG File handling DoS Source: BUGTRAQ Type: UNKNOWN 20070720 2007-07-20 - n.runs-SA-2007.018 - NOD32 Antivirus ASPACK and FSG parsing Divide by Zero Advisory Source: BID Type: Exploit, Patch 24988 Source: CCN Type: BID-24988 ESET NOD32 Antivirus Multiple Remote Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2007-2602 Source: XF Type: UNKNOWN nod32-aspack-fsg-dos(35524) Source: XF Type: UNKNOWN nod32-aspack-fsg-dos(35524) | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||