CVE-2008-3177

Severity CVSS v4.0:
Pending analysis
Type:
CWE-16 Configuration Errors
Publication date:
15/07/2008
Last modified:
09/04/2025

Description

Sophos virus detection engine 2.75 on Linux and Unix, as used in Sophos Email Appliance, Pure Message for Unix, and Sophos Anti-Virus Interface (SAVI), allows remote attackers to cause a denial of service (engine crash) via zero-length MIME attachments.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:sophos:email_appliance:es1000:*:*:*:*:*:*:*
cpe:2.3:h:sophos:email_appliance:es4000:*:*:*:*:*:*:*
cpe:2.3:a:sophos:es1000:*:*:*:*:*:*:*:*
cpe:2.3:a:sophos:es4000:*:*:*:*:*:*:*:*
cpe:2.3:a:sophos:sophos_anti-virus:*:*:*:*:*:*:*:*
cpe:2.3:a:sophos:sophos_puremessage_anti-virus:*:*:*:*:*:*:*:*