CVE-2004-2442

UnknownEPSS 10.64%

Last modified

CVE-2004-2442 is a vulnerability of currently unknown severity. Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Servers and Gateways 4.61 and earlier, and other products, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on the target system.. EPSS estimates a 10.64% chance of exploitation in the next 30 days.

Description

Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Servers and Gateways 4.61 and earlier, and other products, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on the target system.

Metrics

EPSS Probability
10.64%

95.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
F-SecureF-Secure Anti-Virus4.51
F-SecureF-Secure Anti-Virus4.52
F-SecureF-Secure Anti-Virus4.60
F-SecureF-Secure Anti-Virus4.61
F-SecureF-Secure Anti-Virus5.0
F-SecureF-Secure Anti-Virus5.5
F-SecureF-Secure Anti-Virus5.41
F-SecureF-Secure Anti-Virus5.42
F-SecureF-Secure Anti-Virus5.43
F-SecureF-Secure Anti-Virus5.52
F-SecureF-Secure Anti-Virus5.55
F-SecureF-Secure Anti-Virus6.01
F-SecureF-Secure Anti-Virus6.2
F-SecureF-Secure Anti-Virus6.21
F-SecureF-Secure Anti-Virus6.30
F-SecureF-Secure Anti-Virus6.30_sr1
F-SecureF-Secure Anti-Virus6.31
F-SecureF-Secure Anti-Virus2004
F-SecureF-Secure Anti-Virus2005
F-SecureF-Secure For Firewalls6.20
F-SecureF-Secure Internet Security2004
F-SecureF-Secure Internet Security2005
F-SecureF-Secure Personal Express4.5
F-SecureF-Secure Personal Express4.6
F-SecureF-Secure Personal Express4.7
F-SecureF-Secure Personal Express5.0
F-SecureInternet Gatekeeper2.6
F-SecureInternet Gatekeeper6.3
F-SecureInternet Gatekeeper6.4
F-SecureInternet Gatekeeper6.31
F-SecureInternet Gatekeeper6.32
F-SecureInternet Gatekeeper6.41

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2004-2442?
Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Servers and Gateways 4.61 and earlier, and other products, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on the target system.
How severe is CVE-2004-2442?
Severity scoring for CVE-2004-2442 is pending analysis. The EPSS model estimates a 10.64% probability of exploitation in the next 30 days.
How do I fix CVE-2004-2442?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2004-2442?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST