PT-2006-1699 · Trend Micro · Trend Micro Serverprotect

Published

2006-02-10

·

Updated

2018-10-19

·

CVE-2006-0642

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Trend Micro ServerProtect version 5.58
Description The default configuration setting of "Do not scan compressed files when Extracted file count exceeds 500 files" may be too low, allowing remote attackers to bypass anti-virus checks by sending compressed archives containing many small files.
Recommendations For Trend Micro ServerProtect version 5.58, consider increasing the extracted file count limit to a higher value to prevent attackers from bypassing anti-virus checks. As a temporary workaround, monitor the system for messages indicating that the compressed file exceeds specified limits and manually inspect such files to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0642

Affected Products

Trend Micro Serverprotect