CVE-2004-2088: Medium severity Sophos Anti-Virus vulnerability
Published Feb 12, 2004
·Updated
Sophos Anti-Virus 3.78 allows remote attackers to bypass virus scanning by using a qmail generated Delivery Status Notification (DSN) where the original email is not included in the bounce message.
Affected Software
2 affected components
Sophos Anti-Virus=3.4.6
Sophos Anti-Virus=3.78
Remediation
Patch Available
Patch Available
Event History
Feb 12, 2004
CVE Published
05:00 AM
May 19, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2088?
The severity of CVE-2004-2088 is considered medium as it allows attackers to bypass virus scanning.
2
How do I fix CVE-2004-2088?
To fix CVE-2004-2088, update Sophos Anti-Virus to the latest version that addresses this vulnerability.
3
Which versions are affected by CVE-2004-2088?
CVE-2004-2088 affects Sophos Anti-Virus versions 3.4.6 and 3.78.
4
What is CVE-2004-2088?
CVE-2004-2088 is a vulnerability in Sophos Anti-Virus that allows remote attackers to bypass virus scanning using specific Delivery Status Notification emails.
5
Who are the potential attackers for CVE-2004-2088?
Remote attackers who can send specially crafted email bounce messages are the potential threat actors for CVE-2004-2088.