First published: Fri Dec 31 2004(Updated: )
F-Secure Anti-Virus for Microsoft Exchange 6.30 and 6.31 does not properly detect certain password-protected files in a ZIP file, which allows remote attackers to bypass anti-virus protection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
F-Secure Anti-Virus | =6.30 | |
F-Secure Anti-Virus | =6.30_sr1 | |
F-Secure Anti-Virus | =6.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2220 is classified as a high severity vulnerability due to its potential to allow malicious remote attackers to bypass anti-virus protections.
To fix CVE-2004-2220, you should upgrade to a newer version of F-Secure Anti-Virus that properly handles password-protected files.
CVE-2004-2220 affects F-Secure Anti-Virus versions 6.30, 6.30_SR1, and 6.31 for Microsoft Exchange.
CVE-2004-2220 involves certain password-protected files within ZIP archives that are not detected by the software.
Yes, CVE-2004-2220 can potentially lead to data breaches by allowing attackers to deliver malware concealed in password-protected ZIP files.