CVE-2007-2026

The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:amavis:virus_scanner:*:*:*:*:*:*:*:*
cpe:2.3:a:gentoo:file:4.20:*:*:*:*:*:*:*

History

21 Nov 2024, 00:29

Type Values Removed Values Added
References () http://secunia.com/advisories/24918 - () http://secunia.com/advisories/24918 -
References () http://secunia.com/advisories/25394 - () http://secunia.com/advisories/25394 -
References () http://secunia.com/advisories/25544 - () http://secunia.com/advisories/25544 -
References () http://secunia.com/advisories/25578 - () http://secunia.com/advisories/25578 -
References () http://sourceforge.net/mailarchive/forum.php?thread_name=755AF709E5B77E6EA58479D5%40foxx.lsit.ucsb.edu&forum_name=amavis-user - () http://sourceforge.net/mailarchive/forum.php?thread_name=755AF709E5B77E6EA58479D5%40foxx.lsit.ucsb.edu&forum_name=amavis-user -
References () http://www.amavis.org/security/asa-2007-3.txt - () http://www.amavis.org/security/asa-2007-3.txt -
References () http://www.gentoo.org/security/en/glsa/glsa-200704-13.xml - () http://www.gentoo.org/security/en/glsa/glsa-200704-13.xml -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2007:114 - () http://www.mandriva.com/security/advisories?name=MDKSA-2007:114 -
References () http://www.securityfocus.com/archive/1/469520/30/6420/threaded - () http://www.securityfocus.com/archive/1/469520/30/6420/threaded -
References () http://www.securityfocus.com/bid/24146 - () http://www.securityfocus.com/bid/24146 -
References () http://www.vupen.com/english/advisories/2007/2071 - () http://www.vupen.com/english/advisories/2007/2071 -
References () https://bugs.gentoo.org/show_bug.cgi?id=174217 - () https://bugs.gentoo.org/show_bug.cgi?id=174217 -
References () https://issues.rpath.com/browse/RPL-1311 - () https://issues.rpath.com/browse/RPL-1311 -

Information

Published : 2007-04-13 18:19

Updated : 2024-11-21 00:29


NVD link : CVE-2007-2026

Mitre link : CVE-2007-2026

CVE.ORG link : CVE-2007-2026


JSON object : View

Products Affected

amavis

  • virus_scanner

gentoo

  • file