CVE-2006-6960

The Compression Sweep feature in WebRoot Spy Sweeper 4.5.9 and earlier does not handle non-ZIP archives, which allows remote attackers to bypass the malware detection via files with (1) RAR, (2) GZ, (3) TAR, (4) CAB, or (5) ACE compression.
Configurations

Configuration 1 (hide)

cpe:2.3:a:webroot_software:spy_sweeper:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:24

Type Values Removed Values Added
References () http://www.osvdb.org/27536 - Vendor Advisory () http://www.osvdb.org/27536 - Vendor Advisory
References () http://www.securityfocus.com/archive/1/437814/100/200/threaded - () http://www.securityfocus.com/archive/1/437814/100/200/threaded -
References () http://www.sentinel.gr/advisories/SGA-0001.txt - Vendor Advisory () http://www.sentinel.gr/advisories/SGA-0001.txt - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27266 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27266 -

Information

Published : 2007-01-29 16:28

Updated : 2024-11-21 00:24


NVD link : CVE-2006-6960

Mitre link : CVE-2006-6960

CVE.ORG link : CVE-2006-6960


JSON object : View

Products Affected

webroot_software

  • spy_sweeper