Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2263-gvv9-23vp

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypass malware detection.

The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypass malware detection.

EPSS

Процентиль: 79%
0.01341
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
почти 18 лет назад

The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypass malware detection.

EPSS

Процентиль: 79%
0.01341
Низкий

Дефекты

CWE-20