CVE-2008-0308
7.1
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:C
Exploitability: 8.6 / Impact: 6.9
Source: NVD
Description
Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to cause a denial of service (memory consumption) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp).
Affected (13)
Products: Symantec: Scan Engine, Symantec Antivirus Clearswift, Symantec Antivirus Filtering Domino Mpe, Symantec Antivirus Messaging, Symantec Antivirus Microsoft Sharepoint, Symantec Antivirus Ms Isa, Symantec Antivirus Network Attached Storage, Symantec Antivirus Scan Engine, Symantec Antivirus Scan Engine Caching, Symantec Mail Security Exchange
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.1.4.24 | |
| Up to 4.3.16.39 | |
| Up to 3.0.12 | |
| Up to 4.3.16.39 | |
| Up to 4.3.16.39 | |
| Up to 4.3.16.39 | |
| Up to 4.3.16.39 | |
| Up to 4.3.16.39 | |
| Up to 4.3.16.39 | |
| Up to 4.6.5.12 |
Related CWEs
References (12)
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.