CVE-2007-1669 EXPLOIT
7.8
HIGH · CVSS 2.0 · EPSS 12.2% (pctl 96)
Patch early
A public exploit exists.
Description
zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
Scoring
| CVSS | 7.8 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
| EPSS | 12.18% — more likely to be exploited than 96% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-05-09 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| amavis | amavis |
| barracuda networks | barracuda spam firewall |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ZOO - '.ZOO' Decompression Infinite Loop Denial of Service (PoC) | 2007-05-04 |
References
- http://secunia.com/advisories/25122
- http://secunia.com/advisories/25315
- http://securityreason.com/securityalert/2680
- http://www.amavis.org/security/asa-2007-2.txt
- http://www.attrition.org/pipermail/vim/2007-July/001725.html
- http://www.osvdb.org/35795
- http://www.securityfocus.com/archive/1/467646/100/0/threaded
- http://www.securityfocus.com/bid/23823
- http://www.vupen.com/english/advisories/2007/1699
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34080
- http://secunia.com/advisories/25122
- http://secunia.com/advisories/25315
- http://securityreason.com/securityalert/2680
- http://www.amavis.org/security/asa-2007-2.txt
- http://www.attrition.org/pipermail/vim/2007-July/001725.html
- http://www.osvdb.org/35795
- http://www.securityfocus.com/archive/1/467646/100/0/threaded
- http://www.securityfocus.com/bid/23823
- http://www.vupen.com/english/advisories/2007/1699
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34080
→ the Explorer · watch your stack · NVD