MEDIUM · 5.0

CVE-2007-4787

The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypas...

Vulnerability Description

The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypass malware detection.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
SophosScanning Engine2.30.4
SophosSophos Anti-Virus3.4.6

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-4787?

CVE-2007-4787 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypas...

How severe is CVE-2007-4787?

CVE-2007-4787 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-4787?

Check the references section above for vendor advisories and patch information. Affected products include: Sophos Scanning Engine, Sophos Sophos Anti-Virus.