CVE-2004-0552
Summary
| CVE | CVE-2004-0552 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-11-03 05:00:00 UTC |
| Updated | 2017-07-11 01:30:00 UTC |
| Description | Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow malicious code to bypass detection when it is installed, copied, or executed. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sophos | Small Business Suite | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| iDEFENSE | IDEFENSE | www.idefense.com | |
| Kurt Seifried - Security / Security Advisories / KSSA-005 MS-DOS Reserved Device Name Vulnerability In Sophos Anti-Virus | MISC | www.seifried.org | Exploit, Patch, Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.