Denial of Service in Sophos Anti-Virus Due to Bzip2 Archive Processing
CVE-2005-1530
Currently unrated
Summary
A flaw in Sophos Anti-Virus 5.0.1, particularly when the 'Scan inside archive files' feature is enabled, allows remote attackers to exploit a vulnerability in the processing of Bzip2 archives. An attacker can create a specially crafted Bzip2 archive with an oversized 'Extra field length', resulting in excessive CPU usage due to an infinite loop, leading to potential denial of service. Users are advised to review security practices and limit the usage of this feature to mitigate risks.
References
EPSS Score
5% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved