Lucene search

K
cveMitreCVE-2007-2026
HistoryApr 13, 2007 - 6:19 p.m.

CVE-2007-2026

2007-04-1318:19:00
mitre
web.nvd.nist.gov
37
cve-2007-2026
gnu
regular expression
denial of service
cpu consumption
crafted document
os/2 rexx
amavis

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

8.9

Confidence

High

EPSS

0.166

Percentile

96.1%

The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS.

Affected configurations

Nvd
Node
amavisvirus_scanner
OR
gentoofileMatch4.20
VendorProductVersionCPE
amavisvirus_scanner*cpe:2.3:a:amavis:virus_scanner:*:*:*:*:*:*:*:*
gentoofile4.20cpe:2.3:a:gentoo:file:4.20:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

8.9

Confidence

High

EPSS

0.166

Percentile

96.1%