CVE-2007-1669
Summary
| CVE | CVE-2007-1669 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-05-09 00:19:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file. |
Risk And Classification
Primary CVSS: v2.0 7.8 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:L/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Amavis | Amavis | All | All | All | All |
| Hardware | Barracuda Networks | Barracuda Spam Firewall | 3.1.17 | All | All | All |
| Hardware | Barracuda Networks | Barracuda Spam Firewall | 3.1.18 | All | All | All |
| Hardware | Barracuda Networks | Barracuda Spam Firewall | 3.3.0.54 | All | All | All |
| Hardware | Barracuda Networks | Barracuda Spam Firewall | 3.3.01.001 | All | All | All |
| Hardware | Barracuda Networks | Barracuda Spam Firewall | 3.3.03.053 | All | All | All |
| Hardware | Barracuda Networks | Barracuda Spam Firewall | 3.3.03.055 | All | All | All |
| Hardware | Barracuda Networks | Barracuda Spam Firewall | 3.3.15.026 | All | All | All |
| Hardware | Barracuda Networks | Barracuda Spam Firewall | 3.3.3 | All | All | All |
| Hardware | Barracuda Networks | Barracuda Spam Firewall | 3.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Barracuda Spam Firewall Zoo Denial of Service Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Multiple vendors ZOO file decompression infinite loop DoS - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| www.osvdb.org/35795 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Amavis Zoo Denial of Service Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Multiple Vendors Zoo Compression Algorithm Remote Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| [VIM] zoo - amavis - barracuda cross-ref problems | af854a3a-2127-422b-91ae-364da2661108 | www.attrition.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | www.amavis.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.