CVE-2007-1669
Last modified
CVE-2007-1669 is a vulnerability of currently unknown severity. zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.. EPSS estimates a 12.18% chance of exploitation in the next 30 days.
Description
zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Amavis | Amavis | <= 2.4.1 |
References
- http://secunia.com/advisories/25122Patch, Vendor Advisory
- http://secunia.com/advisories/25315Vendor Advisory
- http://secunia.com/advisories/25122Patch, Vendor Advisory
- http://secunia.com/advisories/25315Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1669?
How severe is CVE-2007-1669?
How do I fix CVE-2007-1669?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-1662Perl-Compatible Regular Expression (PCRE) library before 7.3…
- CVE-2007-1663Memory leak in the image message functionality in ekg before…
- CVE-2007-1664ekg before 1:1.7~rc2-1etch1 on Debian GNU/Linux Etch allows …
- CVE-2007-1665Memory leak in the token OCR functionality in ekg before 1:1…
- CVE-2007-1666The processor_request function in the debugger server for Da…
- CVE-2007-1667Multiple integer overflows in (1) the XGetPixel function in …
- CVE-2007-1670Panda Software Antivirus before 20070402 allows remote attac…
- CVE-2007-1671avpack32.dll before 7.3.0.6 in Avira AntiVir allows remote a…
- CVE-2007-1672avast! antivirus before 4.7.981 allows remote attackers to c…
- CVE-2007-1673unzoo.c, as used in multiple products including AMaViS 2.4.1…
- CVE-2007-1674Stack-based buffer overflow in the Alert Service (aolnsrvr.e…
- CVE-2007-1675Buffer overflow in the CRAM-MD5 authentication mechanism in …
Are you affected by CVE-2007-1669?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
