Trend Micro ServerProtect 5.58, and possibly InterScan Messaging Security Suite...
Vulnerability Description
Trend Micro ServerProtect 5.58, and possibly InterScan Messaging Security Suite and InterScan Web Security Suite, have a default configuration setting of "Do not scan compressed files when Extracted file count exceeds 500 files," which may be too low in certain circumstances, which allows remote attackers to bypass anti-virus checks by sending compressed archives containing many small files. NOTE: since this is related to a configuration setting that has an operational impact that might vary depending on the environment, and the product is claimed to report a message when the compressed file exceeds specified limits, perhaps this should not be included in CVE.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-0642
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.packetstormsecurity.org/0602-advisories/Bypass.pdf
- http://www.securityfocus.com/archive/1/424598/100/0/threaded
- http://www.securityfocus.com/archive/1/423896/100/0/threaded
- http://www.securityfocus.com/bid/16483
- http://www.securityfocus.com/archive/1/424172/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24658
- http://www.securityfocus.com/archive/1/423914/100/0/threaded
- http://www.packetstormsecurity.org/filedesc/Bypass.pdf.html
- http://www.securityfocus.com/archive/1/423913/100/0/threaded
More from trend micro
View All →Affected Vendor
trend micro
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.