PT-2004-1660 · Sophos · Sophos Small Business Suite
Publicado
2004-09-28
·
Atualizado
2017-07-11
·
CVE-2004-0552
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Sophos Small Business Suite version 1.00
Description
The issue arises from improper handling of files with names containing reserved MS-DOS device names, such as
LPT1, COM1, AUX, CON, or PRN. This can enable malicious code to evade detection during installation, copying, or execution.Recommendations
For Sophos Small Business Suite version 1.00, consider implementing additional validation for file names to prevent the use of reserved MS-DOS device names, or apply a configuration change to properly handle such files and prevent malicious code from bypassing detection.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sophos Small Business Suite