PT-2006-1699 · Trend Micro · Trend Micro Serverprotect
Published
2006-02-10
·
Updated
2018-10-19
·
CVE-2006-0642
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Trend Micro ServerProtect version 5.58
Description
The default configuration setting of "Do not scan compressed files when Extracted file count exceeds 500 files" may be too low, allowing remote attackers to bypass anti-virus checks by sending compressed archives containing many small files.
Recommendations
For Trend Micro ServerProtect version 5.58, consider increasing the extracted file count limit to a higher value to prevent attackers from bypassing anti-virus checks. As a temporary workaround, monitor the system for messages indicating that the compressed file exceeds specified limits and manually inspect such files to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trend Micro Serverprotect