PT-2006-1699 · Trend Micro · Trend Micro Serverprotect
Publicado
2006-02-10
·
Atualizado
2018-10-19
·
CVE-2006-0642
CVSS v2.0
5.1
Média
| Vetor | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Trend Micro ServerProtect version 5.58
Description
The default configuration setting of "Do not scan compressed files when Extracted file count exceeds 500 files" may be too low, allowing remote attackers to bypass anti-virus checks by sending compressed archives containing many small files.
Recommendations
For Trend Micro ServerProtect version 5.58, consider increasing the extracted file count limit to a higher value to prevent attackers from bypassing anti-virus checks. As a temporary workaround, monitor the system for messages indicating that the compressed file exceeds specified limits and manually inspect such files to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Trend Micro Serverprotect