CVE-2004-2276
Description
F-Secure Anti-Virus fails to detect certain viruses in PKZip archives, allowing Sober.D and Sober.G to bypass initial detection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
F-Secure Anti-Virus fails to detect certain viruses in PKZip archives, allowing Sober.D and Sober.G to bypass initial detection.
Vulnerability
F-Secure Anti-Virus versions 5.41 and 5.42 on Windows, Client Security 5.50 and 5.52, 4.60 for Samba Servers, and 4.52 and earlier for Linux incorrectly scan PKZip archives, failing to detect certain viruses such as Sober.D and Sober.G [1]. This allows the viruses to remain undetected during initial scanning of the archive.
Exploitation
An attacker can craft a PKZip archive containing the Sober.D or Sober.G virus and deliver it to a target system via email, download, or other means. When the F-Secure product scans the archive, it fails to detect the malicious payload due to the flawed archive parsing [1]. No special privileges or network position beyond the ability to deliver the archive is needed.
Impact
Successful exploitation results in the virus not being detected by the antivirus software, allowing the virus to execute and potentially compromise the system. The impact includes information disclosure, system instability, and further propagation, consistent with the behavior of the Sober family of worms [1].
Mitigation
F-Secure has released hotfixes for affected products. Users should update to the latest versions as recommended by F-Secure [1]. Specific hotfixes are available for the Linux version and other affected platforms. No workaround is mentioned in the available references.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 5.41, 5.42 on Windows
- Range: 5.50, 5.52
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5News mentions
0No linked articles in our index yet.