MEDIUM · 5.0

CVE-2004-2442

Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Serv...

Vulnerability Description

Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Servers and Gateways 4.61 and earlier, and other products, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on the target system.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
F-SecureF-Secure Anti-Virus4.51
F-SecureF-Secure For Firewalls6.20
F-SecureF-Secure Internet Security2004
F-SecureF-Secure Personal Express4.5
F-SecureInternet Gatekeeper2.6

References

FAQ

What is CVE-2004-2442?

CVE-2004-2442 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Serv...

How severe is CVE-2004-2442?

CVE-2004-2442 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-2442?

Check the references section above for vendor advisories and patch information. Affected products include: F-Secure F-Secure Anti-Virus, F-Secure F-Secure For Firewalls, F-Secure F-Secure Internet Security, F-Secure F-Secure Personal Express, F-Secure Internet Gatekeeper.