PT-2004-1660 · Sophos · Sophos Small Business Suite

Publicado

2004-09-28

·

Atualizado

2017-07-11

·

CVE-2004-0552

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sophos Small Business Suite version 1.00
Description The issue arises from improper handling of files with names containing reserved MS-DOS device names, such as LPT1, COM1, AUX, CON, or PRN. This can enable malicious code to evade detection during installation, copying, or execution.
Recommendations For Sophos Small Business Suite version 1.00, consider implementing additional validation for file names to prevent the use of reserved MS-DOS device names, or apply a configuration change to properly handle such files and prevent malicious code from bypassing detection.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-0552

Produtos afetados

Sophos Small Business Suite