Title : Sophos Anti-Virus Multiple Archive Handling Detection Bypass Vulnerabilities VUPEN ID : VUPEN/ADV-2007-3078 CVE ID : CVE-2007-4787
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-09-07
Technical Description
Multiple vulnerabilities have been identified in Sophos Anti-Virus products, which could be exploited by attackers or malware to bypass security checks. These issues are caused by errors in the virus detection engine when processing CAB, LZH or RAR archives with modified headers, which could be exploited by attackers or malware to bypass the virus detection feature.