1. Symantec/
  2. Security Response/
  3. Linux.Sorso


July 2, 2003
February 13, 2007 12:03:54 PM
Also Known As:
Worm.Linux.Sorso.a, Backdoor.Linux.Sorso (AVP)
Systems Affected:

Linux.Sorso is a worm that replicates using a Samba buffer overflow exploit. The worm targets vulnerable installations of the Samba server version 2.2.8a and earlier, version 2.0.10 and earlier, and Samba-TNG version 0.3.2 and earlier. The worm also contains code for a backdoor and a Distributed Denial of Service (DDoS) attack and only affects Linux running on Intel x86 platforms.

Antivirus Protection Dates

  • Initial Rapid Release version July 3, 2003
  • Latest Rapid Release version August 8, 2016 revision 023
  • Initial Daily Certified version July 3, 2003
  • Latest Daily Certified version August 9, 2016 revision 001
  • Initial Weekly Certified release date July 9, 2003
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Yuhui Huang

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
2016 Internet Security Threat Report, Volume 21
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube