First published: Thu Feb 12 2004(Updated: )
Sophos Anti-Virus 3.78 allows remote attackers to bypass virus scanning by using a qmail generated Delivery Status Notification (DSN) where the original email is not included in the bounce message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Anti-Virus | =3.4.6 | |
Sophos Anti-Virus | =3.78 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2004-2088 is considered medium as it allows attackers to bypass virus scanning.
To fix CVE-2004-2088, update Sophos Anti-Virus to the latest version that addresses this vulnerability.
CVE-2004-2088 affects Sophos Anti-Virus versions 3.4.6 and 3.78.
CVE-2004-2088 is a vulnerability in Sophos Anti-Virus that allows remote attackers to bypass virus scanning using specific Delivery Status Notification emails.
Remote attackers who can send specially crafted email bounce messages are the potential threat actors for CVE-2004-2088.