peter bassill · operator
$ cve CVE-2007-1669 JSON

CVE-2007-1669 EXPLOIT

7.8
HIGH · CVSS 2.0 · EPSS 12.2% (pctl 96)

Patch early

A public exploit exists.

Description

zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.

Scoring

CVSS7.8 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
EPSS12.18% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2007-05-09
Last modified2026-06-16

Affected (2)

VendorProduct
amavisamavis
barracuda networksbarracuda spam firewall

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD