Trend Micro ServerProtect Extracted File Count Exceed Scan Bypass Weakness
BID:16483
Info
Trend Micro ServerProtect Extracted File Count Exceed Scan Bypass Weakness
| Bugtraq ID: | 16483 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 03 2006 12:00AM |
| Updated: | Feb 03 2006 12:00AM |
| Credit: | Discovered by Mert SARICA <[email protected]>. |
| Vulnerable: |
Trend Micro ServerProtect 5.5.8 |
| Not Vulnerable: | |
Discussion
Trend Micro ServerProtect Extracted File Count Exceed Scan Bypass Weakness
Trend Micro ServerProtect is prone to a scan-bypass weakness.
The issue presents itself because the default value for the 'extracted file count exceeds' setting is specified to 500, allowing an attacker to create a zipped folder containing more than 500 files and malicious code file that will bypass scanning.
Trend Micro ServerProtect 5.58 is reportedly vulnerable to this issue. Other versions may be vulnerable as well.
Trend Micro ServerProtect is prone to a scan-bypass weakness.
The issue presents itself because the default value for the 'extracted file count exceeds' setting is specified to 500, allowing an attacker to create a zipped folder containing more than 500 files and malicious code file that will bypass scanning.
Trend Micro ServerProtect 5.58 is reportedly vulnerable to this issue. Other versions may be vulnerable as well.
Exploit / POC
Trend Micro ServerProtect Extracted File Count Exceed Scan Bypass Weakness
An exploit is not required.
An exploit is not required.
Solution / Fix
Trend Micro ServerProtect Extracted File Count Exceed Scan Bypass Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
Trend Micro ServerProtect Extracted File Count Exceed Scan Bypass Weakness
References:
References:
- ServerProtect for Microsoft Windows/Novell NetWare (Trend Micro)
- Trend Micro ServerProtect Compressed File Scanning Bypass (Mert SARICA)