Sophos Antivirus Scan Severe VulnerabilitiesBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
GFI LANguard - New Version 9 Out Now - Dld 30-day trial!   $100 Free Sweep   Bookmark and Share 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
2009/12/24 0:00:00
2009/7/4 4:33:52
2009/7/3 22:52:05
2009/7/3 22:52:05
2009/7/3 21:32:02
Our Partners
Downloads
Antivirus : Sophos Antivirus Scan Severe Vulnerabilities
Posted by Max on 2006/12/10 4:48:19 (1454 reads)
Antivirus

Several vulnerabilities have been discovered in various Sophos Anti-Virus products, which could be exploited by attackers or malware to take complete control of an affected computer or cause a denial of service.

The first issue is due to a format string error when handling SIT files with specially crafted filenames, which could be exploited by attackers to execute arbitrary commands on a system protected by an exposed application - Sophos.


The second vulnerability is due to a buffer overflow error when processing CPIO files with specially crafted filenames, which could be exploited by attackers to compromise a vulnerable system via a specially crafted file.

Affected Sophos Products
Sophos Anti-Virus for Windows 2000 versions 6.x
Sophos Anti-Virus for Windows XP versions 6.x
Sophos Anti-Virus for Windows 2003 versions 6.x
Sophos Anti-Virus for Windows Vista versions 6.x
Sophos Anti-Virus for Windows NT versions 4.x
Sophos Anti-Virus for Windows 95/98/Me versions 4.x
Sophos Anti-Virus for Mac OS X versions 4.x
Sophos Anti-Virus for Linux versions 5.x
Sophos Anti-Virus for UNIX/Linux versions 4.x
Sophos Anti-Virus for OpenVMS versions 4.x

Solution
Upgrade to virus engine version 2.40.2 :
http://www.sophos.com/support/updates

References
http://www.frsirt.com/english/advisories/2006/4919




Other articles
2009/7/1 13:22:13 - Ultimate Firewall : Location Aware WLAN Firewall by Trapeze Networks
2009/6/28 16:04:09 - New Panda 2010 Ultra-Ligh Security Products
2009/6/24 17:08:30 - Red Condor's Spam Trip Wire Detects a New Computer Virus
2009/6/22 4:32:25 - Finjan's Research Unveils Botnet Trading Platform for Hacked PCs
2009/6/22 4:23:14 - Panda GateDefender Integra Delivers 'Plug and Protect' UTM Security Appliance
2009/6/16 15:42:26 - SanDisk Cruzer Enterprise Wins 2009 Product Innovation Award
2009/6/9 9:02:20 - Weekly $100 Sweepstake Launched By BestSecurityTips.com
2009/6/8 11:29:49 - Paretologic Released a New Free Online Malware Scan
2009/6/8 11:13:17 - New Release of Djigzo Open Source Email Encryption Gateway
2009/5/31 17:27:39 - New BitDefender Online Scanner Released

The comments are owned by the poster. We aren't responsible for their content.