1. /
  2. Security Response/
  3. Linux.Sorso


July 2, 2003
February 13, 2007 12:03:54 PM
Also Known As:
Worm.Linux.Sorso.a, Backdoor.Linux.Sorso (AVP)
Systems Affected:

Linux.Sorso is a worm that replicates using a Samba buffer overflow exploit. The worm targets vulnerable installations of the Samba server version 2.2.8a and earlier, version 2.0.10 and earlier, and Samba-TNG version 0.3.2 and earlier. The worm also contains code for a backdoor and a Distributed Denial of Service (DDoS) attack and only affects Linux running on Intel x86 platforms.

Antivirus Protection Dates

  • Initial Rapid Release version July 3, 2003
  • Latest Rapid Release version September 28, 2010 revision 054
  • Initial Daily Certified version July 3, 2003
  • Latest Daily Certified version September 28, 2010 revision 036
  • Initial Weekly Certified release date July 9, 2003
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Yuhui Huang

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
Internet Security Threat Report