PT-2006-7018 · Kaspersky · Kaspersky Anti-Virus For Linux File Server
Hendrik Weimer
·
Published
2006-12-10
·
Updated
2018-10-17
·
CVE-2006-6408
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Kaspersky Anti-Virus for Linux Mail Servers version 5.5.10
Description
The issue allows remote attackers to bypass virus detection by inserting invalid characters into base64 encoded content in a multipart/mixed MIME file. This can be demonstrated using the EICAR test file, which is a standard test file used to check the functionality of antivirus software.
Recommendations
For Kaspersky Anti-Virus for Linux Mail Servers version 5.5.10, consider updating the software to a version that includes a fix for this issue, or apply any available patches to prevent the bypass of virus detection. As a temporary workaround, consider enhancing the validation of base64 encoded content in multipart/mixed MIME files to detect and prevent the insertion of invalid characters.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kaspersky Anti-Virus For Linux File Server