Vulnerability Description
arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" field in a CHM file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Anti-Spyware | 2007 |
| Broadcom | Anti-Virus For The Enterprise | <= 8 |
| Broadcom | Anti Virus Sdk | All versions |
| Broadcom | Antispyware For The Enterprise | 8 |
| Broadcom | Antivirus Sdk | All versions |
| Broadcom | Brightstor Arcserve Backup | 9.01 |
| Broadcom | Brightstor Arcserve Client | All versions |
| Broadcom | Brightstor Enterprise Backup | 10.5 |
| Broadcom | Brigthstor Arcserve Client For Windows | All versions |
| Broadcom | Common Services | 11 |
| Broadcom | Etrust Antivirus | 8 |
| Broadcom | Etrust Antivirus Gateway | 7.1 |
| Broadcom | Etrust Ez Antivirus | 6.1 |
| Broadcom | Etrust Ez Armor | 1 |
| Broadcom | Etrust Internet Security Suite | 1 |
| Broadcom | Etrust Intrusion Detection | 2.0 |
| Broadcom | Internet Security Suite | 3.0 |
| Broadcom | Secure Content Manager | 1.1 |
| Broadcom | Threat Manager | 8 |
| Broadcom | Unicenter Network And Systems Management | 3.0 |
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=567Patch
- http://secunia.com/advisories/26155PatchVendor Advisory
- http://supportconnectw.ca.com/public/antivirus/infodocs/caprodarclib-secnot.aspPatch
- http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=149847
- http://www.securityfocus.com/archive/1/474601/100/0/threaded
- http://www.securityfocus.com/archive/1/474605/100/100/threaded
- http://www.securityfocus.com/archive/1/474683/100/0/threaded
- http://www.securityfocus.com/bid/25049Patch
- http://www.securitytracker.com/id?1018450
- http://www.vupen.com/english/advisories/2007/2639
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35573
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=567Patch
- http://secunia.com/advisories/26155PatchVendor Advisory
- http://supportconnectw.ca.com/public/antivirus/infodocs/caprodarclib-secnot.aspPatch
- http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=149847
FAQ
What is CVE-2007-3875?
CVE-2007-3875 is a vulnerability with a CVSS score of 4.3 (MEDIUM). arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functio...
How severe is CVE-2007-3875?
CVE-2007-3875 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-3875?
Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Anti-Spyware, Broadcom Anti-Virus For The Enterprise, Broadcom Anti Virus Sdk, Broadcom Antispyware For The Enterprise, Broadcom Antivirus Sdk.