ID

VAR-200412-1211


CVE

CVE-2004-1762


TITLE

F-Secure Anti-Virus for Linux fails to properly detect Sober.D virus

Trust: 0.8

sources: CERT/CC: VU#415734

DESCRIPTION

Unknown vulnerability in F-Secure Anti-Virus (FSAV) 4.52 for Linux before Hotfix 3 allows the Sober.D worm to bypass FASV. A hotfix for this vulnerability has been released. F-Secure Anti-Virus is prone to a remote security vulnerability

Trust: 1.98

sources: NVD: CVE-2004-1762 // CERT/CC: VU#415734 // BID: 90459 // VULHUB: VHN-10192

AFFECTED PRODUCTS

vendor:f securemodel:f-secure anti-virusscope:eqversion:4.50_hotfix_1

Trust: 1.6

vendor:f securemodel:f-secure anti-virusscope:eqversion:4.50_hotfix_2

Trust: 1.6

vendor:f securemodel:f-secure anti-virusscope:eqversion:4.51_hotfix_2

Trust: 1.6

vendor:f securemodel:f-secure anti-virus hotfix linuxscope:eqversion:4.512

Trust: 0.3

vendor:f securemodel:f-secure anti-virus hotfix linuxscope:eqversion:4.502

Trust: 0.3

vendor:f securemodel:f-secure anti-virus hotfix linuxscope:eqversion:4.501

Trust: 0.3

sources: BID: 90459 // CNNVD: CNNVD-200412-329 // NVD: CVE-2004-1762

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2004-1762
value: HIGH

Trust: 1.0

CARNEGIE MELLON: VU#415734
value: 14.43

Trust: 0.8

CNNVD: CNNVD-200412-329
value: HIGH

Trust: 0.6

VULHUB: VHN-10192
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2004-1762
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-10192
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CERT/CC: VU#415734 // VULHUB: VHN-10192 // CNNVD: CNNVD-200412-329 // NVD: CVE-2004-1762

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2004-1762

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200412-329

TYPE

unknown

Trust: 0.6

sources: CNNVD: CNNVD-200412-329

EXTERNAL IDS

db:CERT/CCid:VU#415734

Trust: 2.8

db:SECUNIAid:11089

Trust: 2.5

db:NVDid:CVE-2004-1762

Trust: 2.0

db:XFid:15432

Trust: 0.9

db:CNNVDid:CNNVD-200412-329

Trust: 0.7

db:BIDid:90459

Trust: 0.4

db:VULHUBid:VHN-10192

Trust: 0.1

sources: CERT/CC: VU#415734 // VULHUB: VHN-10192 // BID: 90459 // CNNVD: CNNVD-200412-329 // NVD: CVE-2004-1762

REFERENCES

url:http://support.f-secure.com/enu/corporate/downloads/hotfixes/av-linux-hotfixes.shtml

Trust: 2.8

url:http://www.kb.cert.org/vuls/id/415734

Trust: 2.0

url:http://secunia.com/advisories/11089

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/15432

Trust: 1.1

url:http://xforce.iss.net/xforce/xfdb/15432

Trust: 0.9

url:http://secunia.com/advisories/11089/

Trust: 0.8

url:ftp://ftp.f-secure.com/support/hotfix/fsav/fsav-4.52-hotfix3.tgz

Trust: 0.8

sources: CERT/CC: VU#415734 // VULHUB: VHN-10192 // BID: 90459 // CNNVD: CNNVD-200412-329 // NVD: CVE-2004-1762

CREDITS

Unknown

Trust: 0.3

sources: BID: 90459

SOURCES

db:CERT/CCid:VU#415734
db:VULHUBid:VHN-10192
db:BIDid:90459
db:CNNVDid:CNNVD-200412-329
db:NVDid:CVE-2004-1762

LAST UPDATE DATE

2024-08-14T15:36:06.138000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#415734date:2004-03-18T00:00:00
db:VULHUBid:VHN-10192date:2017-07-11T00:00:00
db:BIDid:90459date:2004-12-31T00:00:00
db:CNNVDid:CNNVD-200412-329date:2005-10-20T00:00:00
db:NVDid:CVE-2004-1762date:2017-07-11T01:31:20.013

SOURCES RELEASE DATE

db:CERT/CCid:VU#415734date:2004-03-18T00:00:00
db:VULHUBid:VHN-10192date:2004-12-31T00:00:00
db:BIDid:90459date:2004-12-31T00:00:00
db:CNNVDid:CNNVD-200412-329date:2004-12-31T00:00:00
db:NVDid:CVE-2004-1762date:2004-12-31T05:00:00