Sophos Anti-Virus 3.78 allows remote attackers to bypass virus scanning by using a qmail generated Delivery Status Notification (DSN) where the original email is not included in the bounce message.
Link | Tags |
---|---|
http://securitytracker.com/id?1009042 | vdb entry |
http://secunia.com/advisories/10855 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15192 | vdb entry |
http://www.sophos.com/support/news/#mime-378 | patch |
http://www.securityfocus.com/bid/9650 | vdb entry patch vendor advisory |