PT-2004-3334 · F Secure · F-Secure Windows Servers+3
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-2442
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
F-Secure Anti-Virus products, including:
F-Secure Workstation versions 5.43 and earlier
F-Secure Windows Servers versions 5.50 and earlier
F-Secure MIMEsweeper versions 5.50 and earlier
F-Secure Anti-Virus for Linux Servers and Gateways versions 4.61 and earlier
Description:
A multiple interpretation error in F-Secure Anti-Virus products allows remote attackers to bypass antivirus protection. This is achieved by using a compressed file with both local and global headers set to zero, which does not prevent the file from being opened on the target system.
Recommendations:
For F-Secure Workstation versions 5.43 and earlier, update to a version later than 5.43 to resolve the issue.
For F-Secure Windows Servers versions 5.50 and earlier, update to a version later than 5.50 to resolve the issue.
For F-Secure MIMEsweeper versions 5.50 and earlier, update to a version later than 5.50 to resolve the issue.
For F-Secure Anti-Virus for Linux Servers and Gateways versions 4.61 and earlier, update to a version later than 4.61 to resolve the issue.
As a temporary workaround, consider restricting the opening of compressed files with suspicious headers to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
F-Secure Anti-Virus For Linux Servers/Gateways
F-Secure Mimesweeper
F-Secure Windows Servers
F-Secure Workstation