CVE-2008-3177
Last modified
CVE-2008-3177 is a vulnerability of currently unknown severity. Sophos virus detection engine 2.75 on Linux and Unix, as used in Sophos Email Appliance, Pure Message for Unix, and Sophos Anti-Virus Interface (SAVI), allows remote attackers to cause a denial of service (engine crash) via zero-length MIME attachments.. EPSS estimates a 5.13% chance of exploitation in the next 30 days.
Description
Sophos virus detection engine 2.75 on Linux and Unix, as used in Sophos Email Appliance, Pure Message for Unix, and Sophos Anti-Virus Interface (SAVI), allows remote attackers to cause a denial of service (engine crash) via zero-length MIME attachments.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sophos | Es1000 | All versions |
| Sophos | Es4000 | All versions |
| Sophos | Sophos Anti-Virus | All versions |
| Sophos | Sophos Puremessage Anti-Virus | All versions |
References
- http://secunia.com/advisories/31037Vendor Advisory
- http://secunia.com/advisories/31037Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-3177?
How severe is CVE-2008-3177?
How do I fix CVE-2008-3177?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-3170Apple Safari allows web sites to set cookies for country-spe…
- CVE-2008-3171Apple Safari sends Referer headers containing https URLs to …
- CVE-2008-3172Opera allows web sites to set cookies for country-specific t…
- CVE-2008-3173Microsoft Internet Explorer allows web sites to set cookies …
- CVE-2008-3174Unspecified vulnerability in the kmxfw.sys driver in CA Host…
- CVE-2008-3175Integer underflow in rxRPC.dll in the LGServer service in th…
- CVE-2008-3178Unrestricted file upload vulnerability in upload_pictures.ph…
- CVE-2008-3179Directory traversal vulnerability in website.php in Web 2 Bu…
- CVE-2008-3180Multiple cross-site scripting (XSS) vulnerabilities in uploa…
- CVE-2008-3181Unrestricted file upload vulnerability in upload.php in Cont…
- CVE-2008-3182Stack-based buffer overflow in DAP.exe in Download Accelerat…
- CVE-2008-3183PHP remote file inclusion vulnerability in ktmlpro/includes/…
Are you affected by CVE-2008-3177?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
