Lucene search

K
cveMitreCVE-2007-4787
HistorySep 10, 2007 - 9:17 p.m.

CVE-2007-4787

2007-09-1021:17:00
CWE-20
mitre
web.nvd.nist.gov
27
virus detection engine
sophos anti-virus
file processing
malware detection
cve-2007-4787

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.094

Percentile

94.8%

The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypass malware detection.

Affected configurations

Nvd
Node
sophosscanning_engineMatch2.30.4
OR
sophossophos_anti-virusMatch3.4.6
OR
sophossophos_anti-virusMatch3.78
OR
sophossophos_anti-virusMatch3.78d
OR
sophossophos_anti-virusMatch3.79
OR
sophossophos_anti-virusMatch3.80
OR
sophossophos_anti-virusMatch3.81
OR
sophossophos_anti-virusMatch3.82
OR
sophossophos_anti-virusMatch3.83
OR
sophossophos_anti-virusMatch3.84
OR
sophossophos_anti-virusMatch3.85
OR
sophossophos_anti-virusMatch3.86
OR
sophossophos_anti-virusMatch3.90
OR
sophossophos_anti-virusMatch3.91
OR
sophossophos_anti-virusMatch3.95
OR
sophossophos_anti-virusMatch3.96
OR
sophossophos_anti-virusMatch4.04
OR
sophossophos_anti-virusMatch4.05
OR
sophossophos_anti-virusMatch4.5.3
OR
sophossophos_anti-virusMatch4.5.4
OR
sophossophos_anti-virusMatch4.5.11
OR
sophossophos_anti-virusMatch4.5.12
OR
sophossophos_anti-virusMatch4.7.1
OR
sophossophos_anti-virusMatch4.7.2
OR
sophossophos_anti-virusMatch5.0.1
OR
sophossophos_anti-virusMatch5.0.2
OR
sophossophos_anti-virusMatch5.0.4
OR
sophossophos_anti-virusMatch5.1
OR
sophossophos_anti-virusMatch5.2.0
OR
sophossophos_anti-virusMatch5.2.1
OR
sophossophos_anti-virusMatch6.0
OR
sophossophos_anti-virusMatch6.5
OR
sophossophos_anti-virusMatch6.5.4_r2
OR
sophossophos_anti-virusMatch6.5.8
OR
sophossophos_anti-virusMatch7.0
VendorProductVersionCPE
sophosscanning_engine2.30.4cpe:2.3:a:sophos:scanning_engine:2.30.4:*:*:*:*:*:*:*
sophossophos_anti-virus3.4.6cpe:2.3:a:sophos:sophos_anti-virus:3.4.6:*:*:*:*:*:*:*
sophossophos_anti-virus3.78cpe:2.3:a:sophos:sophos_anti-virus:3.78:*:*:*:*:*:*:*
sophossophos_anti-virus3.78dcpe:2.3:a:sophos:sophos_anti-virus:3.78d:*:*:*:*:*:*:*
sophossophos_anti-virus3.79cpe:2.3:a:sophos:sophos_anti-virus:3.79:*:*:*:*:*:*:*
sophossophos_anti-virus3.80cpe:2.3:a:sophos:sophos_anti-virus:3.80:*:*:*:*:*:*:*
sophossophos_anti-virus3.81cpe:2.3:a:sophos:sophos_anti-virus:3.81:*:*:*:*:*:*:*
sophossophos_anti-virus3.82cpe:2.3:a:sophos:sophos_anti-virus:3.82:*:*:*:*:*:*:*
sophossophos_anti-virus3.83cpe:2.3:a:sophos:sophos_anti-virus:3.83:*:*:*:*:*:*:*
sophossophos_anti-virus3.84cpe:2.3:a:sophos:sophos_anti-virus:3.84:*:*:*:*:*:*:*
Rows per page:
1-10 of 351

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.094

Percentile

94.8%

Related for CVE-2007-4787