F-Secure Anti Virus Fails to Detect Sober.D/G Worms Within Zip Archives
|
|
SecurityTracker Alert ID: 1010279
|
|
SecurityTracker URL: http://securitytracker.com/id?1010279
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: May 25 2004
|
Impact: Host/resource access via network
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Version(s): Workstation and Server versions 5.41, 5.42; Client Security versions 5.50, 5.52
|
Description: A vulnerability was reported in F-Secure Anti Virus. The software does not detect Sober.D and Sober.G worms in certain cases.
The vendor reported that Sober.D and Sober.G worms contained inside PKZip archives (*.zip) are not detected by the software. As a result, a remote user can send a worm though or to an ostensibly protected system.
|
Impact: A remote user can send a worm in a zip archive through or to the system without detection.
|
Solution: The vendor has released the following hotfixes.
For F-Secure Anti Virus 5.41/5.42 for Workstations, use FSAV 5.42/5.41 Hotfix
3:
ftp://ftp.f-secure.com/support/hotfix/fsav/fsavwk552-05-signed.fsfix
For F-Secure Anti-Virus 5.41/5.42 for File Servers,
use FSAV 5.41/5.42 for Servers Hotfix 13:
ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsavsr541-13-signed.fsfix
For
F-Secure Anti Virus Client Security 5.50, 5.52, use FSAVCS Hotfix 10 (Anti-Virus Hotfix 5):
ftp://ftp.f-secure.com/support/hotfix/fsavcs/fsavwk552-05-signed.fsfix
|
Vendor URL: support.f-secure.com/enu/corporate/downloads/hotfixes/ (Links to External Site)
|
Cause: State error
|
Underlying OS: Windows (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Tue, 25 May 2004 12:57:25 -0400
Subject: F-Secure Anti Virus hotfix for Sober.D and Sober.G detection
|
> Sober.D and Sober.G worms inside PKZip archives (*.zip) are not detected.
F-Secure Anti Virus 5.41/5.42 for Workstations
FSAV 5.42/5.41 Hotfix 3:
ftp://ftp.f-secure.com/support/hotfix/fsav/fsavwk552-05-signed.fsfix
F-Secure Anti-Virus 5.41/5.42 for File Servers
FSAV 5.41/5.42 for Servers Hotfix 13:
ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsavsr541-13-signed.fsfix
F-Secure Anti Virus Client Security 5.50, 5.52
FSAVCS Hotfix 10 (Anti-Virus Hotfix 5):
ftp://ftp.f-secure.com/support/hotfix/fsavcs/fsavwk552-05-signed.fsfix
|
|