PT-2010-3119 · F Secure+1 · Protection Service For Business - Server Security+13

Published

2010-04-15

·

Updated

2010-04-16

·

CVE-2010-1425

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions F-Secure Internet Security versions 2010 and earlier Anti-Virus for Microsoft Exchange versions 9 and earlier Anti-Virus for MIMEsweeper versions 5.61 and earlier Internet Gatekeeper for Windows versions 6.61 and earlier Internet Gatekeeper for Linux versions 4.02 and earlier Anti-Virus versions 2010 and earlier Home Server Security version 2009 Protection Service for Consumers versions 9 and earlier Protection Service for Business - Workstation security versions 9 and earlier Protection Service for Business - Server Security versions 8 and earlier Protection Service for E-mail and Server security versions 9 and earlier Mac Protection build 8060 and earlier Client Security versions 9 and earlier
Description The issue is related to improper detection of malware in crafted archives, including 7Z, GZIP, CAB, or RAR archives. This makes it easier for remote attackers to avoid detection.
Recommendations For F-Secure Internet Security versions 2010 and earlier, update to a newer version to resolve the issue. For Anti-Virus for Microsoft Exchange versions 9 and earlier, update to a newer version to resolve the issue. For Anti-Virus for MIMEsweeper versions 5.61 and earlier, update to a newer version to resolve the issue. For Internet Gatekeeper for Windows versions 6.61 and earlier, update to a newer version to resolve the issue. For Internet Gatekeeper for Linux versions 4.02 and earlier, update to a newer version to resolve the issue. For Anti-Virus versions 2010 and earlier, update to a newer version to resolve the issue. For Home Server Security version 2009, update to a newer version to resolve the issue. For Protection Service for Consumers versions 9 and earlier, update to a newer version to resolve the issue. For Protection Service for Business - Workstation security versions 9 and earlier, update to a newer version to resolve the issue. For Protection Service for Business - Server Security versions 8 and earlier, update to a newer version to resolve the issue. For Protection Service for E-mail and Server security versions 9 and earlier, update to a newer version to resolve the issue. For Mac Protection build 8060 and earlier, update to a newer version to resolve the issue. For Client Security versions 9 and earlier, update to a newer version to resolve the issue. As a temporary workaround, consider restricting the handling of crafted 7Z, GZIP, CAB, or RAR archives until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-1425

Affected Products

Anti-Virus
Anti-Virus For Mimesweeper
Anti-Virus For Microsoft Exchange
Client Security
F-Secure Internet Security
Home Server Security
Internet Gatekeeper For Linux
Internet Gatekeeper For Windows
Mac Protection
Exchange Server
Protection Service For Business - Server Security
Protection Service For Business - Workstation Security
Protection Service For Consumers
Protection Service For E-Mail/Server Security