The Compression Sweep feature in WebRoot Spy Sweeper 4.5.9 and earlier does not handle non-ZIP archives, which allows remote attackers to bypass the malware detection via files with (1) RAR, (2) GZ, (3) TAR, (4) CAB, or (5) ACE compression.
References
Configurations
History
21 Nov 2024, 00:24
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.osvdb.org/27536 - Vendor Advisory | |
References | () http://www.securityfocus.com/archive/1/437814/100/200/threaded - | |
References | () http://www.sentinel.gr/advisories/SGA-0001.txt - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/27266 - |
Information
Published : 2007-01-29 16:28
Updated : 2024-11-21 00:24
NVD link : CVE-2006-6960
Mitre link : CVE-2006-6960
CVE.ORG link : CVE-2006-6960
JSON object : View
Products Affected
webroot_software
- spy_sweeper
CWE