CVE-2004-0937
Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.8%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 14.79% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- archive zip/archive zip · broadcom/brightstor arcserve backup · broadcom/etrust antivirus · broadcom/etrust antivirus gateway · broadcom/etrust ez antivirus · broadcom/etrust ez armor · broadcom/etrust intrusion detection · broadcom/etrust secure content manager · broadcom/inoculateit · ca/etrust antivirus · ca/etrust secure content manager · eset software/nod32 antivirus · kaspersky lab/kaspersky anti-virus · mcafee/antivirus engine · rav antivirus/rav antivirus desktop · rav antivirus/rav antivirus for file servers · rav antivirus/rav antivirus for mail servers · sophos/sophos anti-virus · sophos/sophos puremessage anti-virus · sophos/sophos small business suite · +3 more
- Source
- cve@mitre.org
References
- http://www.idefense.com/application/poi/display?id=153&type=vulnerabilities&flashstatus=true
- http://www.kb.cert.org/vuls/id/968818US Government Resource
- http://www.securityfocus.com/bid/11448Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17761
- http://www.idefense.com/application/poi/display?id=153&type=vulnerabilities&flashstatus=true
- http://www.kb.cert.org/vuls/id/968818US Government Resource
- http://www.securityfocus.com/bid/11448Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17761
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.