Sophos Antivirus Scan Severe VulnerabilitiesBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
Internet security & monitoring for networks - Dld trial!   Get A Free iPod   Bookmark and Share 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
2009/12/24 0:00:00
2009/11/20 17:37:24
2009/11/20 17:37:24
2009/11/20 15:43:34
2009/11/20 15:43:34
Our Partners
Downloads
Antivirus : Sophos Antivirus Scan Severe Vulnerabilities
Posted by Max on 2006/12/10 4:48:19 (1588 reads)
Antivirus

Several vulnerabilities have been discovered in various Sophos Anti-Virus products, which could be exploited by attackers or malware to take complete control of an affected computer or cause a denial of service.

The first issue is due to a format string error when handling SIT files with specially crafted filenames, which could be exploited by attackers to execute arbitrary commands on a system protected by an exposed application - Sophos.


The second vulnerability is due to a buffer overflow error when processing CPIO files with specially crafted filenames, which could be exploited by attackers to compromise a vulnerable system via a specially crafted file.

Affected Sophos Products
Sophos Anti-Virus for Windows 2000 versions 6.x
Sophos Anti-Virus for Windows XP versions 6.x
Sophos Anti-Virus for Windows 2003 versions 6.x
Sophos Anti-Virus for Windows Vista versions 6.x
Sophos Anti-Virus for Windows NT versions 4.x
Sophos Anti-Virus for Windows 95/98/Me versions 4.x
Sophos Anti-Virus for Mac OS X versions 4.x
Sophos Anti-Virus for Linux versions 5.x
Sophos Anti-Virus for UNIX/Linux versions 4.x
Sophos Anti-Virus for OpenVMS versions 4.x

Solution
Upgrade to virus engine version 2.40.2 :
http://www.sophos.com/support/updates

References
http://www.frsirt.com/english/advisories/2006/4919




Other articles
2009/11/3 14:55:39 - BitDefender Top Ten Malware Threats for October 09
2009/11/3 14:29:38 - Nov. 09 Microsoft Security Intelligence Report
2009/10/7 15:19:17 - StopSign AntiVirus and Anti-Malware is Windows 7 Compatible
2009/10/7 15:11:26 - New Outlook Backup and Migration Software By Disk Doctors
2009/9/30 4:20:57 - Microsoft Security Essentials, FREE Security Tool Just Released
2009/9/28 14:31:52 - New Rogue Antispyware Cloaked To Infects Computers
2009/9/9 4:31:49 - Trend Micro Proves Leadership in URL Filtering and Web Security
2009/9/9 4:16:20 - New Free Tool to Clean Conficker Once and For All
2009/9/1 8:37:11 - Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010 Out Now
2009/9/1 7:54:50 - NEW P2P Advertising Network Protects Users Against Lawsuits And Identity Theft

The comments are owned by the poster. We aren't responsible for their content.