Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:STC:DL:SOPHOS-MAL-VISIO1

Severity

Medium

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Sophos Anti-Virus Malicious Visio File Attack1

Release Date

2015/09/30

Update Number

2541

Supported Platforms

idp-5.1.110151004+, isg-3.5.141421+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Sophos Anti-Virus Malicious Visio File Attack1


This signature detects attempts to exploit a known vulnerability in Sophos Anti-Virus. Sophos is vulnerable to a signed integer overflow. If a malformed Microsoft Visio file is scanned for viruses by Sophos AV, the Sophos process could be taken over and arbitrary code executed as SYSTEM. Microsoft Visio does not need to be installed in order to exploit Sophos AV in this manner. Because of the complexity of Visio files, it is possible this signature can false positive and therefore should only be used in Internet-facing policies.

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out