Sophos antivirus protection bypassed
Kieren McCarthy (Techworld.com) 13/02/2004 07:40:57

Sophos PLC's anti-virus software can be bypassed by a virus-laden e-mail if it doesn't contain any MIME boundary definitions, the company has admitted.

MIME, or Multipurpose Internet Mail Extensions, is the basic protocol used for sending graphic, audio and video on e-mail. But Sophos has found that Delivery Status Notifications generated by qmail mail servers (the second-largest in number on the Net) that are infected with the MyDoom virus slip through the anti-virus software undetected.

Only qmail servers set up to include the original e-mail in the bounced e-mail will not include MIME boundary definitions and so slip through. But it still remains a significant security hole considering the number of qmail servers (around one million) and that the impact of many modern viruses and worms come from the emails automatically created by their appearance.

On top of that, a separate bug in the scanning engine means that the anti-virus software can be used to launch a denial of service attack on your PC if certain MIME headings are used. An "unexpectedly terminated MIME header" will send the application into an infinite loop, eating system resources in the process, the company said.

In effect, an unpatched version of the software will soon prove a liability rather than offering any sort of protection as not only will virus writers quickly latch onto the idea but the software itself can be used to bring down your computer.

Both vulnerabilities apply to the latest version of the software - 3.78 - but an updated version that patches the holes is available for download - 3.78d.

For more information on the holes plus links to downloads for different OSes, go to http://www.sophos.com/support/news/#mime-378.

More about Sophos
Recommend this article?
Yes0 votes
No0 votes

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Enter the fully qualified URL, eg. http://www.example.com/
Users posting comments agree to the PC World comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Syndicate content
 
Gift Guide
MWave
Samsung

CXO Latest

LED Advisor
 

Colour your world with Samsung

A chance to win with every
Samsung Consumable purchase*