CVE-2009-1783
Multiple FRISK Software F-Prot anti-virus products, including Antivirus for Exchange, Linux on IBM zSeries, Linux x86 File Servers, Linux x86 Mail Servers, Linux x86 Workstations, Solaris Mail Servers, Antivirus for Windows, and others, allow remote…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple FRISK Software F-Prot anti-virus products, including Antivirus for Exchange, Linux on IBM zSeries, Linux x86 File Servers, Linux x86 Mail Servers, Linux x86 Workstations, Solaris Mail Servers, Antivirus for Windows, and others, allow remote attackers to bypass malware detection via a crafted CAB archive.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 3.44% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- f-prot/f-prot antivirus · f-prot/f-prot aves · f-prot/f-prot milter
- Source
- cve@mitre.org
References
- http://blog.zoller.lu/2009/04/advisory-f-prot-frisk-cab-bypass.html
- http://www.securityfocus.com/archive/1/503393/100/0/threaded
- http://www.securityfocus.com/bid/34896
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50427
- http://blog.zoller.lu/2009/04/advisory-f-prot-frisk-cab-bypass.html
- http://www.securityfocus.com/archive/1/503393/100/0/threaded
- http://www.securityfocus.com/bid/34896
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50427
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.