CVE-2008-6904
high · 10Multiple unspecified vulnerabilities in Sophos SAVScan 4.33.0 for Linux, and possibly other products and versions, allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via crafted files that have been packed with (1) armadillo, (2) asprotect, or (3) asprotectSKE.
10
CVSS
10.6%
EPSS (exploit prob.)
96th
EPSS percentile
2009-08-06
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| sophos | anti-virus | 4.7.18 |
| sophos | anti-virus | 4.7.18 |
| sophos | anti-virus | 4.9.18 |
| sophos | anti-virus | 4.37.0 |
| sophos | anti-virus | 6.4.5 |
| sophos | anti-virus | 7.0.5 |
| sophos | anti-virus7.6.3 | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://marc.info/?l=bugtraq&m=122893252316489&w=2
- http://www.ivizsecurity.com/security-advisory-iviz-sr-08015.html
- http://www.securityfocus.com/bid/32748
- http://www.sophos.com/support/knowledgebase/article/50611.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52443
- http://marc.info/?l=bugtraq&m=122893252316489&w=2
- http://www.ivizsecurity.com/security-advisory-iviz-sr-08015.html
- http://www.securityfocus.com/bid/32748
- http://www.sophos.com/support/knowledgebase/article/50611.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52443
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2008-6904