Sophos Anti-Virus 3.78 allows remote attackers to bypass virus scanning by using a qmail generated Delivery Status Notification (DSN) where the original email is not included in the bounce message.
| Software | From | Fixed in |
|---|---|---|
| sophos / sophos_anti-virus | 3.78 | 3.78.x |
| sophos / sophos_anti-virus | 3.4.6 | 3.4.6.x |