Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Sophos Anti-Virus for Windows and for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted UPX packed file, resulting from an "integer cast around". NOTE: as of 20070828, the vendor says this is a DoS and the researcher says this allows code execution, but the researcher is reliable.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sophos Antivirus UPX文件解析拒绝服务漏洞
Vulnerability Description
Sophos Anti-Virus是英国Sophos公司的一套适用于多种操作系统的反病毒软件。该软件可实时侦测和清除病毒、间谍软件、木马和蠕虫,确保台式机和笔记本电脑的全面网络保护。 Sophos Anti-Virus在处理畸形格式的UPX拒绝服务漏洞,如果用户受骗打开了恶意的UPX压缩可执行文件的话,就可能触发死循环,导致引擎崩溃或临时文件耗尽所有磁盘空间。
CVSS Information
N/A
Vulnerability Type
N/A