Secunia CSI7
Advisories
Research
Forums
Create Profile
Our Commitment
PSI
PSI API
CSI
OSI
xSI
Vulnerabilities
Programs
Open Discussions
My Threads
Create Thread
Statistics
About

Forum Thread: PSI detects wrong version number

You are currently viewing a forum thread in the Secunia Community Forum. Please note that opinions expressed here are not of Secunia but solely reflect those of the user who wrote it.

This thread was submitted in the following forum:
Programs

Relating to this vendor:
Comodo Group
And, this specific program:
Comodo Internet Security 4.x

This thread has been marked as locked.
Haareken PSI detects wrong version number
Member 9th Jun, 2010 17:42
Ranking: 0
Posts: 2
User Since: 9th Jun, 2010
System Score: N/A
Location: NO
PSI detects version 4.1.18600.916, but there isn't such a release available from Comodo.
The latest Comodo Internet Security is version 4.1.149672.916 and SA40094 was fixed in this release:
http://personalfirewall.comodo.com/release_notes.h...

Prince Avalanche RE: PSI detects wrong version number
Member 9th Jun, 2010 17:54
Score: 1
Posts: 4
User Since: 14th Apr 2010
System Score: N/A
Location: US
It is showing the same thing for me also.

--
Prince Avalanche
Was this reply relevant?
+1
-0
This user no longer exists RE: PSI detects wrong version number
Member 9th Jun, 2010 20:07
Last edited on 9th Jun, 2010 20:18 PSI is reporting on the version # of cfp.exe. However, the update link Secunia is pointing to does not update cfp.exe to a newer version. So has Comodo not resolved the issue? If so Secunia should state, "Insecure, no solution". Or is this a false positive by Secunia?

Windows 7 x64
x64 Comodo Firewall 4.1.150349.920
Was this reply relevant?
+0
-0
peterspragge RE: PSI detects wrong version number
Member 9th Jun, 2010 20:21
Score: 0
Posts: 15
User Since: 1st Nov 2008
System Score: N/A
Location: N/A
I am confused. I have just updated my Comodo Firewall and I am told that it is up to date but my version is 4.1.150349.920. I too am getting a category 1 threat message from Secunia for 4.1.18600.916
Was this reply relevant?
+0
-0
rastern RE: PSI detects wrong version number
Member 10th Jun, 2010 01:25
Score: 0
Posts: 2
User Since: 25th Jul 2009
System Score: N/A
Location: N/A
Same problem here.
I have 2 computers with PSI and Comodo firewall. I received an alert about a new update from Comodo and installed the update on one but not the other. The updated one now shows the same version numbers on the other posts and that PSI shows it is unsecured.

On the non-updated computer Comodo and PSI both show that the old version (v.3.14.63867.584) is secure and patched.

???
Was this reply relevant?
+0
-0
ve2mrx RE: PSI detects wrong version number
Member 10th Jun, 2010 07:52
Score: -1
Posts: 22
User Since: 16th Feb 2008
System Score: 99%
Location: Montreal, CA
I guess Comodo forgot to update the external file version?

Like Adobe did on one of their past Acrobat reader updates...
Was this reply relevant?
+0
-0
E.Jeppesen RE: PSI detects wrong version number
Secunia Official 10th Jun, 2010 14:32
Score: 220
Posts: 618
User Since: 24th Nov 2008
System Score: N/A
Location: Copenhagen, DK
In Comodo Internet Security you can click "More" and then "About". That will show you which version you have installed. To be patched and secure you need version 4.1.149672.916 or later.

The file version information in the files from Comodo Internet Security currently seem to report a wrong version. The PSI gets its information from these files. We have just updated our detection and version rules accordingly. Could I ask you to perform a full system scan with the PSI and report the result in this thread?
Haareken RE: PSI detects wrong version number
Member 10th Jun, 2010 16:58
Score: 0
Posts: 2
User Since: 9th Jun 2010
System Score: N/A
Location: NO
Last edited on 10th Jun, 2010 17:00
A full system scan does not rate the latest CIS version as insecure (it does not show up in the results), you seem to have fixed it. :)
Was this reply relevant?
+0
-0
rastern RE: PSI detects wrong version number
Member 10th Jun, 2010 22:57
Score: 0
Posts: 2
User Since: 25th Jul 2009
System Score: N/A
Location: N/A
Today's PSI scan states that Comodo Firewall is now secure. PSI says the current patched version is 4.1.149672.916,

I checked my Comodo Firewall install for the current version under 'About'. It says the installed version on my system is v 4.1.150349.920. That was the version I had installed yesterday. Yesterday, according to their website that release date was June 2, 2010.

After I ran the PSI scan, I checked for a new update to see if Comodo had changed anything. It showed the latest release date in now June 9. 2010. After installing the new update, Comodo still shows the latest version is 4.1.1503493.920. No version change.

I ran another full PSI scan. It still says my latest Comodo firewall is secure, but it also still shows the version it scanned was 4.1.149672.916.

I can't decide if I have the latest patch or not.
Was this reply relevant?
+0
-0
peterspragge RE: PSI detects wrong version number
Member 11th Jun, 2010 08:44
Score: 0
Posts: 15
User Since: 1st Nov 2008
System Score: N/A
Location: N/A
My findings are the same. Previously Comodo has told me when I needed to update the firewall. What surprised me a little this time is that the first message came from Secunia and then when I checked for updates on the More tab, Comodo told me that an update was available.
Was this reply relevant?
+0
-0
E.Jeppesen RE: PSI detects wrong version number
Secunia Official 11th Jun, 2010 10:33
Score: 220
Posts: 618
User Since: 24th Nov 2008
System Score: N/A
Location: Copenhagen, DK
Currently, the incorrect file version information in the files from Comodo Internet Security makes the PSI report a different version than the interface of Comodo Internet Security. Since our changes to our detection and version rules however, the program should no longer be detected as insecure unless it really is insecure.

As mentioned you can also see if your version of Comodo Internet Security is secure by clicking "More" and then "About". To be patched and secure you need version 4.1.149672.916 or later.

This thread has been marked as locked.


 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Reports
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2014 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability - Disclaimer