CVE-2004-2442
Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Servers and Gateways 4.61 and earlier, and other products, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on the target system.
- Affected products
- F-Secure Anti-Virus For Linux Servers/Gateways, F-Secure Mimesweeper, F-Secure Windows Servers, F-Secure Workstation
- F-secure F-secure Anti-virus
- = 4.51, 4.52, 4.60, 4.61, 5.0, 5.5, 5.41, 5.42, 5.43, 5.52, 5.55, 6.01, 6.2, 6.21, 6.30, 6.30_sr1, 6.31, 2004, 2005
- F-secure F-secure For Firewalls
- = 6.20
- F-secure F-secure Internet Security
- = 2004, 2005
- F-secure F-secure Personal Express
- = 4.5, 4.6, 4.7, 5.0
- F-secure Internet Gatekeeper
- = 2.6, 6.3, 6.4, 6.31, 6.32, 6.41
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 10.6% (95th percentile)
- NVD status
- Modified
- Published
- 2005-08-20
CVE-2004-2442 at NVD
1 known exploit for CVE-2004-2442
Proof-of-concept code and exploit modules indexed by Sploitus