CVE-2009-1348
Summary
| CVE | CVE-2009-1348 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-04-30 20:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Email Servers, Email Gateway, and Active Virus Defense allows remote attackers to bypass virus detection via (1) an invalid Headflags field in a malformed RAR archive, (2) an invalid Packsize field in a malformed RAR archive, or (3) an invalid Filelength field in a malformed ZIP archive. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:H/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mcafee | Active Virusscan | All | All | All | All |
| Application | Mcafee | Active Virus Defense | All | All | All | All |
| Application | Mcafee | Email Gateway | All | All | All | All |
| Application | Mcafee | Internet Security Suite | All | All | All | All |
| Application | Mcafee | Internet Security Suite | 2004 | All | All | All |
| Application | Mcafee | Internet Security Suite | 2005 | All | All | All |
| Application | Mcafee | Internet Security Suite | 2006 | All | All | All |
| Application | Mcafee | Internet Security Suite | 2009 | All | All | All |
| Application | Mcafee | Securityshield For Email Servers | All | All | All | All |
| Application | Mcafee | Securityshield For Microsoft Isa Server | All | All | All | All |
| Application | Mcafee | Securityshield For Microsoft Sharepoint | All | All | All | All |
| Application | Mcafee | Total Protection | 2009 | All | All | All |
| Application | Mcafee | Total Protection For Endpoint | All | All | All | All |
| Application | Mcafee | Virusscan Commandline | All | All | All | All |
| Application | Mcafee | Virusscan Enterprise | All | All | All | All |
| Application | Mcafee | Virusscan Enterprise | - | - | linux | All |
| Application | Mcafee | Virusscan Enterprise | - | - | sap | All |
| Application | Mcafee | Virusscan Enterprise | - | - | storage | All |
| Application | Mcafee | Virusscan Plus | 2009 | All | All | All |
| Application | Mcafee | Virusscan Usb | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Secdev - Thierry Zoller: Mcafee multiple bypasses/evasions (ZIP,RAR) | af854a3a-2127-422b-91ae-364da2661108 | blog.zoller.lu | |
| McAfee KnowledgeBase - | af854a3a-2127-422b-91ae-364da2661108 | kc.mcafee.com | Patch, Vendor Advisory |
| McAfee Products Archive Handling Security Bypass - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| McAfee Products RAR/ZIP Files Scan Evasion Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.