The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypass malware detection.
https://exchange.xforce.ibmcloud.com/vulnerabilities/36502
http://www.vupen.com/english/advisories/2007/3078
http://www.sophos.com/support/knowledgebase/article/29146.html
http://www.securityfocus.com/bid/25574