F-Secure Anti-Virus bypass Sober.D and Sober.G detection
| fsecure-sober-detection-bypass (16243) |
Description:
F-Secure Anti-Virus could allow a remote attacker to bypass Sober.D and Sober.G virus detection when the viruses are embedded in a PKZip archive.
Platforms Affected:
- F-Secure, Anti-Virus 5.41
- F-Secure, Anti-Virus 5.42
- F-Secure, Anti-Virus Client Security 5.50 and 5.52
Remedy:
For F-Secure Anti-Virus 5.42/5.41 for Workstations:
Apply HotFix 3, available from the F-Secure Web site. See References.
For F-Secure Anti-Virus 5.41/5.42 for File Servers:
Apply HotFix 13, available from the F-Secure Web site. See References.
For F-Secure Anti Virus Client Security 5.50 and 5.52:
Apply HotFix 10, available from the F-Secure Web site. See References.
—OR—
For F-Secure Anti Virus Client Security 5.50 and 5.52:
Upgrade to the latest version (5.52 Service Release 1 or later), available from the F-Secure Web site. See References.
Consequences:
Bypass Security
References:
- F-Secure Web site, F-Secure Support Pages at http://support.f-secure.com/enu/home/.
- CVE-2004-2276: F-Secure Anti-Virus 5.41 and 5.42 on Windows, Client Security 5.50 and 5.52, 4.60 for Samba Servers, and 4.52 and earlier for Linux does not properly detect certain viruses in a PKZip archive, which allows viruses such as Sober.D and Sober.G to bypass initial detection.
- OSVDB ID: 6409: F-Secure Anti-Virus PKZip Virus Detection Bypass
- SA11699: F-Secure Anti-Virus Archived Virus Detection Bypass Vulnerability
Reported:
May 25, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
