CVE-2005-1530

Sophos Anti-Virus 5.0.1 - Denial of Service via Bzip2 Archive with Large Extra Field Length

Title source: llm
STIX 2.1

Description

Sophos Anti-Virus 5.0.1, with "Scan inside archive files" enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large 'Extra field length' value.

References (4)

Core 4
Core References
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14270
Patch, Vendor Advisory third-party-advisory x_refsource_idefense
http://www.idefense.com/application/poi/display?id=283&type=vulnerabilities&flashstatus=true
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1014488
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/21373

Scores

EPSS 0.0598
EPSS Percentile 90.8%

Details

Status published
Products (19)
sophos/sophos_anti-virus 3.4.6
sophos/sophos_anti-virus 3.78
sophos/sophos_anti-virus 3.78d
sophos/sophos_anti-virus 3.79
sophos/sophos_anti-virus 3.80
sophos/sophos_anti-virus 3.81
sophos/sophos_anti-virus 3.82
sophos/sophos_anti-virus 3.83
sophos/sophos_anti-virus 3.84
sophos/sophos_anti-virus 3.85
... and 9 more
Published Jul 19, 2005
Tracked Since Feb 18, 2026