// For flags

CVE-2007-4578

 

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Sophos Anti-Virus for Windows and for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted UPX packed file, resulting from an "integer cast around". NOTE: as of 20070828, the vendor says this is a DoS and the researcher says this allows code execution, but the researcher is reliable.

Sophos Anti-Virus para Windows y para Unix/Linux anterior a 2.48.0 permite a atacantes remotos provocar una denegación de servicio (caída) y posiblemente ejecutar código de su elección mediante un archivo empaquetado con UPX manipulado, resultado de una "conversión de vuelta de entero" (integer cast around). NOTA: a fecha de 28/08/2007, el fabricante dice que esto es una denegación de servicio y el investigador dice que permite ejecución de código, pero el investigador es fiable.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-08-28 CVE Reserved
  • 2007-08-28 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-10-23 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-189: Numeric Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
3.4.6
Search vendor "Sophos" for product "Anti-virus" and version "3.4.6"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
3.78
Search vendor "Sophos" for product "Anti-virus" and version "3.78"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
3.78d
Search vendor "Sophos" for product "Anti-virus" and version "3.78d"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
3.79
Search vendor "Sophos" for product "Anti-virus" and version "3.79"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
3.80
Search vendor "Sophos" for product "Anti-virus" and version "3.80"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
3.81
Search vendor "Sophos" for product "Anti-virus" and version "3.81"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
3.82
Search vendor "Sophos" for product "Anti-virus" and version "3.82"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
3.83
Search vendor "Sophos" for product "Anti-virus" and version "3.83"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
3.84
Search vendor "Sophos" for product "Anti-virus" and version "3.84"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
3.85
Search vendor "Sophos" for product "Anti-virus" and version "3.85"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
3.86
Search vendor "Sophos" for product "Anti-virus" and version "3.86"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
3.90
Search vendor "Sophos" for product "Anti-virus" and version "3.90"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
3.91
Search vendor "Sophos" for product "Anti-virus" and version "3.91"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
3.95
Search vendor "Sophos" for product "Anti-virus" and version "3.95"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
3.96.0
Search vendor "Sophos" for product "Anti-virus" and version "3.96.0"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
4.03
Search vendor "Sophos" for product "Anti-virus" and version "4.03"
linux
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
4.04
Search vendor "Sophos" for product "Anti-virus" and version "4.04"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
4.05
Search vendor "Sophos" for product "Anti-virus" and version "4.05"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
4.5.3
Search vendor "Sophos" for product "Anti-virus" and version "4.5.3"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
4.5.4
Search vendor "Sophos" for product "Anti-virus" and version "4.5.4"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
4.5.11
Search vendor "Sophos" for product "Anti-virus" and version "4.5.11"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
4.5.12
Search vendor "Sophos" for product "Anti-virus" and version "4.5.12"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
4.7.1
Search vendor "Sophos" for product "Anti-virus" and version "4.7.1"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
4.7.2
Search vendor "Sophos" for product "Anti-virus" and version "4.7.2"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
5.0.1
Search vendor "Sophos" for product "Anti-virus" and version "5.0.1"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
5.0.2
Search vendor "Sophos" for product "Anti-virus" and version "5.0.2"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
5.0.4
Search vendor "Sophos" for product "Anti-virus" and version "5.0.4"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
5.0.9
Search vendor "Sophos" for product "Anti-virus" and version "5.0.9"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
5.0.9
Search vendor "Sophos" for product "Anti-virus" and version "5.0.9"
linux
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
5.1
Search vendor "Sophos" for product "Anti-virus" and version "5.1"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
5.2
Search vendor "Sophos" for product "Anti-virus" and version "5.2"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
5.2.1
Search vendor "Sophos" for product "Anti-virus" and version "5.2.1"
-
Affected
Sophos
Search vendor "Sophos"
Anti-virus
Search vendor "Sophos" for product "Anti-virus"
6.5
Search vendor "Sophos" for product "Anti-virus" and version "6.5"
-
Affected
Sophos
Search vendor "Sophos"
Scanning Engine
Search vendor "Sophos" for product "Scanning Engine"
2.30.4
Search vendor "Sophos" for product "Scanning Engine" and version "2.30.4"
-
Affected
Sophos
Search vendor "Sophos"
Scanning Engine
Search vendor "Sophos" for product "Scanning Engine"
2.40.2
Search vendor "Sophos" for product "Scanning Engine" and version "2.40.2"
-
Affected
Sophos
Search vendor "Sophos"
Small Business Suite
Search vendor "Sophos" for product "Small Business Suite"
4.04
Search vendor "Sophos" for product "Small Business Suite" and version "4.04"
-
Affected
Sophos
Search vendor "Sophos"
Small Business Suite
Search vendor "Sophos" for product "Small Business Suite"
4.05
Search vendor "Sophos" for product "Small Business Suite" and version "4.05"
-
Affected