First published: Fri Dec 31 2004(Updated: )
Computer Associates eTrust Antivirus EE 6.0 through 7.0 allows remote attackers to bypass virus scanning by including a password-protected file in a ZIP file, which causes eTrust to scan only the password protected file and skip the other files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom eTrust Antivirus EE | =6.0 | |
Broadcom eTrust Antivirus EE | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2305 is considered a medium severity vulnerability that allows bypassing of virus scanning on specific versions of eTrust Antivirus.
CVE-2004-2305 exploits the ability to include a password-protected file in a ZIP file, causing eTrust Antivirus to skip scanning the other files.
CVE-2004-2305 affects Broadcom eTrust Antivirus EE versions 6.0 and 7.0.
To fix CVE-2004-2305, upgrade to a version of eTrust Antivirus that addresses this vulnerability.
The risks associated with CVE-2004-2305 include the potential for malware to be introduced to a system without detection.