Sophos Anti-Virus CAB, LZH, and RAR File Scan Evasion Vulnerability
BID:25574
Info
Sophos Anti-Virus CAB, LZH, and RAR File Scan Evasion Vulnerability
| Bugtraq ID: | 25574 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-4787 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 06 2007 12:00AM |
| Updated: | May 07 2015 05:35PM |
| Credit: | Thierry Zoller of n.runs AG is credited with discovering this issue. |
| Vulnerable: |
Sophos Anti-Virus Engine 2.30.4 Sophos Anti-Virus 6.5.8 Sophos Anti-Virus 6.5.4 R2 Sophos Anti-Virus 6.5 Sophos Anti-Virus 5.2.1 Sophos Anti-Virus 5.2 Sophos Anti-Virus 5.0.4 Sophos Anti-Virus 5.0.2 Sophos Anti-Virus 5.0.1 Sophos Anti-Virus 4.7.2 Sophos Anti-Virus 4.7.1 Sophos Anti-Virus 4.5.12 Sophos Anti-Virus 4.5.11 Sophos Anti-Virus 4.5.4 Sophos Anti-Virus 4.5.3 Sophos Anti-Virus 3.96 .0 Sophos Anti-Virus 3.95 Sophos Anti-Virus 3.91 Sophos Anti-Virus 3.90 Sophos Anti-Virus 3.86 Sophos Anti-Virus 3.85 Sophos Anti-Virus 3.84 Sophos Anti-Virus 3.83 Sophos Anti-Virus 3.82 Sophos Anti-Virus 3.81 Sophos Anti-Virus 3.80 Sophos Anti-Virus 3.79 Sophos Anti-Virus 3.78 d Sophos Anti-Virus 3.78 Sophos Anti-Virus 3.4.6 Sophos Anti-Virus 7.0 Sophos Anti-Virus 6.0 Sophos Anti-Virus 5.1 Sophos Anti-Virus 4.05 Sophos Anti-Virus 4.04 |
| Not Vulnerable: |
Sophos Anti-Virus Engine 2.49 Sophos Anti-Virus 7.01 |
Discussion
Sophos Anti-Virus CAB, LZH, and RAR File Scan Evasion Vulnerability
Sophos Anti-Virus is prone to a vulnerability that may allow certain compressed archives to bypass the scan engine.
Successful exploits will allow attackers to distribute files containing malicious code that will not be detected by the antivirus application.
Sophos Anti-Virus is prone to a vulnerability that may allow certain compressed archives to bypass the scan engine.
Successful exploits will allow attackers to distribute files containing malicious code that will not be detected by the antivirus application.
Exploit / POC
Sophos Anti-Virus CAB, LZH, and RAR File Scan Evasion Vulnerability
An attacker may exploit this issue by distributing maliciously crafted archive files.
An attacker may exploit this issue by distributing maliciously crafted archive files.
Solution / Fix
Sophos Anti-Virus CAB, LZH, and RAR File Scan Evasion Vulnerability
Solution:
The vendor has released scanning engine version 2.49.0 to address this issue. Users are advised to install the latest available version of Sophos Anti-Virus, which contains the updated engine. Please contact the vendor for details on obtaining and applying the appropriate updates.
Solution:
The vendor has released scanning engine version 2.49.0 to address this issue. Users are advised to install the latest available version of Sophos Anti-Virus, which contains the updated engine. Please contact the vendor for details on obtaining and applying the appropriate updates.
References
Sophos Anti-Virus CAB, LZH, and RAR File Scan Evasion Vulnerability
References:
References: