A vulnerability has been discovered in F-Secure Anti-Virus for MS Exchange, which may prevent detection of malware in certain archives.
bb2297adabcabdaa680484a6360d87b55765bfdb694dbdea225a540c4d52044e
==========================================================================
F-Secure Anti-Virus for Microsoft Exchange
Version 6.30 and 6.31 Post-Release Fix
Copyright (c) 1993-2004 F-Secure Corporation. All Rights Reserved.
==========================================================================
INDEX
o Summary
o More Information
o How to Apply
SUMMARY
This post-release fix is for the following products/versions:
o F-Secure Anti-Virus for Microsoft Exchange 6.30
o F-Secure Anti-Virus for Microsoft Exchange 6.30 Service Release 1
o F-Secure Anti-Virus for Microsoft Exchange 6.31
This post-release version includes the following fixes:
o CTS#36132 Password protected files in ZIP archives may pass detection
o CTS#36151 Nested archives not dropped when marked as unsafe
TECHNICAL DETAILS
This hotfix improves the handling of password protected and nested archive files.
Prior to this hotfix, some password protected files were not detected inside a ZIP
archive. After installing this hotfix the product detects those correctly. Nested
archive files were not quarantined even if F-Secure Content Scanner Server was
configured to report them as "unsafe".
After applying this hotfix the password protected files and nested archives will
be quarantined in the "infect" quarantine directory, if quarantining is turned on
in the product settings.
It should be noted that the settings related to the nested archives and password
protected files in ZIP archives also affect the manual scanning. If the product
is configured to treat the password protected or nested archives as unsafe, manual
scanning will remove those from the Microsoft Exchange Server.
Installing this hotfix requires a reboot.
F-Secure recommends all the F-Secure Anti-Virus for Microsoft Exchange users
to apply this hotfix.
OTHER INFORMATION
This fix includes the following files:
File Name File Version MD5 Checksum
-------------------------------------------------------------------
fsavvsi2.dll 6.31.33.0 7b4b8408f65d8a0760c8b1bd4b64c413
fssmtphk.dll 6.31.33.0 bfa9350b5676f56e3f1444e37987f345
fsstrods.exe 6.31.33.0 36bc1c84df0ab82c50541a9f655f29cd
For additional information, please visit F-Secure Support Center at:
https://support.f-secure.com/
HOW TO APPLY THE POSTFIX
o Unpack all files from the package into a temporary folder on the
local machine.
o Open this folder in Windows Explorer and then double-click
"fsavmse631-02.fsfix".
-- end of file --