NVD Vulnerability Detail
Search Exploit, PoC
CVE-2006-0642
Summary

Trend Micro ServerProtect 5.58, and possibly InterScan Messaging Security Suite and InterScan Web Security Suite, have a default configuration setting of "Do not scan compressed files when Extracted file count exceeds 500 files," which may be too low in certain circumstances, which allows remote attackers to bypass anti-virus checks by sending compressed archives containing many small files. NOTE: since this is related to a configuration setting that has an operational impact that might vary depending on the environment, and the product is claimed to report a message when the compressed file exceeds specified limits, perhaps this should not be included in CVE.

Publication Date Feb. 10, 2006, 8:02 p.m.
Registration Date Jan. 29, 2021, 3:31 p.m.
Last Update Oct. 20, 2018, 12:45 a.m.
CVSS2.0 : MEDIUM
Score 5.1
Vector AV:N/AC:H/Au:N/C:P/I:P/A:P
攻撃元区分(AV) ネットワーク
攻撃条件の複雑さ(AC)
攻撃前の認証要否(Au) 不要
機密性への影響(C)
完全性への影響(I)
可用性への影響(A)
Get all privileges. いいえ
Get user privileges いいえ
Get other privileges いいえ
User operation required はい
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:a:trend_micro:interscan_messaging_security_suite:*:*:*:*:*:*:*:*
cpe:2.3:a:trend_micro:interscan_web_security_suite:*:*:*:*:*:*:*:*
cpe:2.3:a:trend_micro:serverprotect:5.58:*:emc:*:*:*:*:*
Related information, measures and tools
Common Vulnerabilities List