Overview
Sophos Antivirus contains multiple vulnerabilities including memory corruption issues and design flaws.
Description
Sophos Antivirus contains multiple vulnerabilities including memory corruption issues and design flaws. Tavis Ormandy's security report lists the following vulnerabilities. These vulnerabilities are new and separate from Tavis' 2011 report entitled "Sophail: A Critical Analysis of Sophos Antivirus." [PDF] Additional details are available in Tavis Ormandy's full report entitled, "Sophail: Applied attacks against Sophos Antivirus." [PDF] A response from Sophos has been posted to their blog: "Sophos products and Tavis Ormandy." Integer overflow parsing Visual Basic 6 controls |
Impact
An attacker may be able to gain control of the system, escalate privileges, or cause a denial-of-service condition. |
Solution
Apply an Update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 9.7 | AV:N/AC:L/Au:N/C:C/I:C/A:P |
Temporal | 8.7 | E:POC/RL:U/RC:C |
Environmental | 6.5 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Tavis Ormandy for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
CVE IDs: | None |
Date Public: | 2012-11-05 |
Date First Published: | 2012-11-05 |
Date Last Updated: | 2012-11-06 13:17 UTC |
Document Revision: | 40 |