VulnerabilityModified
CVE-2005-3499
Frisk F-Prot Antivirus allows remote attackers to bypass protection via a ZIP file with a version header greater than 15, which prevents F-Prot from decompressing and analyzing the file.
HIGH 7.5EPSS 3.34%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.34%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Frisk F-Prot Antivirus allows remote attackers to bypass protection via a ZIP file with a version header greater than 15, which prevents F-Prot from decompressing and analyzing the file.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 3.34% probability · 88th percentile
- CISA KEV
- Not listed
- Affected
- frisk software/f-prot antivirus
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0073.html
- http://securitytracker.com/id?1015148
- http://thierry.sniff-em.com/research/fprot.html
- http://www.osvdb.org/20865
- http://www.securityfocus.com/archive/1/415637/30/0/threaded
- http://www.securityfocus.com/archive/1/502370/100/0/threaded
- http://www.securityfocus.com/bid/15293
- http://www.zoller.lu/research/fprot.htm
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22967
- http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0073.html
- http://securitytracker.com/id?1015148
- http://thierry.sniff-em.com/research/fprot.html
- http://www.osvdb.org/20865
- http://www.securityfocus.com/archive/1/415637/30/0/threaded
- http://www.securityfocus.com/archive/1/502370/100/0/threaded
- http://www.securityfocus.com/bid/15293
- http://www.zoller.lu/research/fprot.htm
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22967
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.