CVE Vulnerabilities

CVE-2008-0308

Published: Feb 28, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.1 HIGH
AV:N/AC:M/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to cause a denial of service (memory consumption) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp).

Affected Software

NameVendorStart VersionEnd Version
Scan_engineSymantec*5.1.4.24 (including)
Symantec_antivirus_clearswiftSymantec*4.3.16.39 (including)
Symantec_antivirus_filtering_domino_mpeSymantec*3.0.12 (including)
Symantec_antivirus_messagingSymantec*4.3.16.39 (including)
Symantec_antivirus_microsoft_sharepointSymantec*4.3.16.39 (including)
Symantec_antivirus_ms_isaSymantec*4.3.16.39 (including)
Symantec_antivirus_network_attached_storageSymantec*4.3.16.39 (including)
Symantec_antivirus_scan_engineSymantec*4.3.16.39 (including)
Symantec_antivirus_scan_engine_cachingSymantec*4.3.16.39 (including)
Symantec_mail_security_exchangeSymantec*4.6.5.12 (including)
Symantec_mail_security_exchangeSymantec*5.0.4.363 (including)

References