Kaspersky AntiVirus Engine 6.0.1.411 for Windows and 5.5-10 for Linux allows remote attackers to cause a denial of service (CPU consumption) via a crafted UPX compressed file with a negative offset, which triggers an infinite loop during decompression.
2007-03-06T01:19:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 7.8 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:C
10.0
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | microsoft | all_windows | abstract_cpe | No |
Application | kaspersky_lab | kaspersky_antivirus_engine | 6.0.1.411 | Yes |
Operating System | linux | linux_kernel | * | No |
Application | kaspersky_lab | kaspersky_antivirus_engine | 5.5.10 | Yes |