25122Third-party advisory
http://secunia.com/advisories/25122 CVE-2007-1669
ZOO - '.ZOO' Decompression Infinite Loop Denial of Service (PoC)
Record summary
CVE-2007-1669 has a selected CVSS score of 7.8; EIP currently links 1 catalogued exploit.
Description
zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBZOO - '.ZOO' Decompression Infinite Loop Denial of Service (PoC)ExploitDB exploitby Jean-SébastienNot analyzed1 file
References
1125315Third-party advisory
http://secunia.com/advisories/25315 2680Third-party advisory
http://securityreason.com/securityalert/2680 amavis.orgConfirmation
http://www.amavis.org/security/asa-2007-2.txt 20070724 zoo - amavis - barracuda cross-ref problemsmailing list
http://www.attrition.org/pipermail/vim/2007-July/001725.html 35795vdb entry
http://www.osvdb.org/35795 20070504 Multiple vendors ZOO file decompression infinite loop DoSmailing list
http://www.securityfocus.com/archive/1/467646/100/0/threaded 23823vdb entry
http://www.securityfocus.com/bid/23823 ADV-2007-1699vdb entry
http://www.vupen.com/english/advisories/2007/1699 multiple-vendor-zoo-dos(34080)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/34080 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-1669