CVE-2005-1551

Sophos Anti-Virus <3.93 - Code Injection

Title source: llm
STIX 2.1

Description

Sophos Anti-Virus 3.93 does not check downloaded files for viruses when they have only been written, which creates a race condition and may allow remote attackers to bypass virus protection if the file is executed before the antivirus starts on system reboot.

References (2)

Core 2
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111566827411376&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/20519

Scores

EPSS 0.0077
EPSS Percentile 73.8%

Details

Status published
Products (1)
sophos/sophos_anti-virus 3.93
Published May 14, 2005
Tracked Since Feb 18, 2026