CVE-2006-0642
Trend Micro ServerProtect 5.58, and possibly InterScan Messaging Security Suite and InterScan Web Security Suite, have a default configuration setting of "Do not scan compressed files when Extracted file count exceeds 500 files," which may be too low in certain circumstances, which allows remote attackers to bypass anti-virus checks by sending compressed archives containing many small files. NOTE: since this is related to a configuration setting that has an operational impact that might vary depending on the environment, and the product is claimed to report a message when the compressed file exceeds specified limits, perhaps this should not be included in CVE.
Published:Feb 10, 2006
Last Modified:Apr 16, 2026
EPS:Feb 10, 2006
EPSS Score:0.00842
CVSS Score:5.1
Affected Products
Vendor
Product
Action
Vendor
Trend Micro
Product
Interscan Messaging Security Suite
Trend Micro
Interscan Messaging Security Suite
Vendor
Trend Micro
Product
Interscan Web Security Suite
Trend Micro
Interscan Web Security Suite
Vendor
Trend Micro
Product
Serverprotect
Trend Micro
Serverprotect
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
