Multiple Vendor Antivirus Software Zip Files Detection Evasion Vulnerability
BID:11448
Info
Multiple Vendor Antivirus Software Zip Files Detection Evasion Vulnerability
| Bugtraq ID: | 11448 |
| Class: | Design Error |
| CVE: |
CVE-2004-0932 CVE-2004-0933 CVE-2004-0934 CVE-2004-0937 CVE-2004-0935 CVE-2004-0936 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | An anonymous researcher discovered this issue. |
| Vulnerable: |
Sophos Small Business Suite 1.0 Sophos PureMessage Anti-Virus 4.6 Sophos Anti-Virus 3.86 Sophos Anti-Virus 3.85 Sophos Anti-Virus 3.84 Sophos Anti-Virus 3.83 Sophos Anti-Virus 3.82 Sophos Anti-Virus 3.81 Sophos Anti-Virus 3.80 Sophos Anti-Virus 3.79 Sophos Anti-Virus 3.78 d Sophos Anti-Virus 3.78 Sophos Anti-Virus 3.4.6 S.u.S.E. Linux Personal 9.2 RAV AntiVirus RAV AntiVirus for Mail Servers 8.4.2 RAV AntiVirus RAV AntiVirus for File Servers 1.0 RAV AntiVirus RAV AntiVirus Desktop 8.6 McAfee Antivirus Engine 4.3.20 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 Kaspersky Labs Antivirus Scanning Engine 5.0 Kaspersky Labs Antivirus Scanning Engine 4.0 Kaspersky Labs Antivirus Scanning Engine 3.0 Gentoo Linux 1.4 Gentoo Linux Eset NOD32 Antivirus 1.0 13 Eset NOD32 Antivirus 1.0 12 Eset NOD32 Antivirus 1.0 11 Computer Associates InoculateIT 6.0 Computer Associates eTrust Secure Content Manager 1.1 Computer Associates eTrust Secure Content Manager 1.0 SP1 Computer Associates eTrust Secure Content Manager 1.0 Computer Associates eTrust Intrusion Detection 1.5 Computer Associates eTrust Intrusion Detection 1.4.5 Computer Associates eTrust Intrusion Detection 1.4.1 .13 Computer Associates eTrust EZ Armor 2.4 Computer Associates eTrust EZ Armor 2.3 Computer Associates eTrust EZ Armor 2.0 Computer Associates eTrust EZ Antivirus 6.3 Computer Associates eTrust EZ Antivirus 6.2 Computer Associates eTrust EZ Antivirus 6.1 Computer Associates eTrust Antivirus for the Gateway 7.1 Computer Associates eTrust Antivirus for the Gateway 7.0 Computer Associates eTrust Antivirus 7.1 Computer Associates eTrust Antivirus 7.0 SP2 Computer Associates eTrust Antivirus 7.0 Computer Associates BrightStor ARCServe Backup for Windows 11.1 Archive::Zip Archive::Zip 1.13 |
| Not Vulnerable: |
Archive::Zip Archive::Zip 1.14 |
Discussion
Multiple Vendor Antivirus Software Zip Files Detection Evasion Vulnerability
Multiple Vendor Antivirus applications are reported vulnerable to a zip file detection evasion vulnerability. This vulnerability may allow maliciously crafted zip files to avoid being scanned and detected.
A remote attacker can craft a malicious zip archive and send it a vulnerable user. The malicious archive can bypass the protection provided by a vulnerable antivirus program, giving users a false sense of security. If the user opens and executes the file, this attack can result in a malicious code infection.
This issue is reported to affected products offered by McAfee, Computer Associates, Kaspersky, Sophos, Eset and RAV.
Latest antivirus products by Symantec, Bitdefender, Trend Micro and Panda are not vulnerable to this issue.
Multiple Vendor Antivirus applications are reported vulnerable to a zip file detection evasion vulnerability. This vulnerability may allow maliciously crafted zip files to avoid being scanned and detected.
A remote attacker can craft a malicious zip archive and send it a vulnerable user. The malicious archive can bypass the protection provided by a vulnerable antivirus program, giving users a false sense of security. If the user opens and executes the file, this attack can result in a malicious code infection.
This issue is reported to affected products offered by McAfee, Computer Associates, Kaspersky, Sophos, Eset and RAV.
Latest antivirus products by Symantec, Bitdefender, Trend Micro and Panda are not vulnerable to this issue.
Exploit / POC
Multiple Vendor Antivirus Software Zip Files Detection Evasion Vulnerability
An exploit is not required.
A proof of concept exploit targeting multiple products is available:
An exploit is not required.
A proof of concept exploit targeting multiple products is available:
Solution / Fix
Multiple Vendor Antivirus Software Zip Files Detection Evasion Vulnerability
Solution:
Various vendors have released updates and corrected this issue. Other vendors are reported to release fixes in the near future. Please see references and contact the vendor for more information.
Gentoo Linux has released an advisory (GLSA 200410-31) that fixes the Archive-Zip package and apparently resolves this issue. Gentoo Linux advises that all Archive::Zip users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-perl/Archive-Zip-1.14"
For more information please see the referenced Gentoo Linux advisory.
Mandrake Linux has released an advisory (MDKSA-2004:118) dealing with this issue in their perls Archive::Zip package. Please see the referenced advisory for more information.
SuSE Linux has released a fixed version of perls Archive::Zip module to resolve this issue.
Computer Associates eTrust Secure Content Manager 1.0
Computer Associates eTrust Secure Content Manager 1.0 SP1
Computer Associates eTrust Secure Content Manager 1.1
Archive::Zip Archive::Zip 1.13
Computer Associates eTrust Intrusion Detection 1.4.1 .13
Computer Associates eTrust Intrusion Detection 1.4.5
Computer Associates eTrust Intrusion Detection 1.5
Mandriva Linux Mandrake 10.1
Mandriva Linux Mandrake 10.1 x86_64
Computer Associates eTrust EZ Armor 2.0
Computer Associates eTrust EZ Armor 2.3
Computer Associates eTrust EZ Armor 2.4
McAfee Antivirus Engine 4.3.20
Computer Associates InoculateIT 6.0
Computer Associates eTrust EZ Antivirus 6.1
Computer Associates eTrust EZ Antivirus 6.2
Computer Associates eTrust EZ Antivirus 6.3
Computer Associates eTrust Antivirus for the Gateway 7.0
Computer Associates eTrust Antivirus 7.0
Computer Associates eTrust Antivirus 7.1
Computer Associates eTrust Antivirus for the Gateway 7.1
Solution:
Various vendors have released updates and corrected this issue. Other vendors are reported to release fixes in the near future. Please see references and contact the vendor for more information.
Gentoo Linux has released an advisory (GLSA 200410-31) that fixes the Archive-Zip package and apparently resolves this issue. Gentoo Linux advises that all Archive::Zip users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-perl/Archive-Zip-1.14"
For more information please see the referenced Gentoo Linux advisory.
Mandrake Linux has released an advisory (MDKSA-2004:118) dealing with this issue in their perls Archive::Zip package. Please see the referenced advisory for more information.
SuSE Linux has released a fixed version of perls Archive::Zip module to resolve this issue.
Computer Associates eTrust Secure Content Manager 1.0
-
Computer Associates eTrust Secure Content Manager Solutions & Patches
http://supportconnectw.ca.com/premium/etrust/etrust_scm/downloads/etru stscm_updates.asp
Computer Associates eTrust Secure Content Manager 1.0 SP1
-
Computer Associates eTrust Secure Content Manager Solutions & Patches
http://supportconnectw.ca.com/premium/etrust/etrust_scm/downloads/etru stscm_updates.asp
Computer Associates eTrust Secure Content Manager 1.1
-
Computer Associates eTrust Secure Content Manager Solutions & Patches
http://supportconnectw.ca.com/premium/etrust/etrust_scm/downloads/etru stscm_updates.asp
Archive::Zip Archive::Zip 1.13
-
SuSE perl-Archive-Zip-1.14-3.1.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/perl-Archive-Zip- 1.14-3.1.i586.rpm
Computer Associates eTrust Intrusion Detection 1.4.1 .13
-
Computer Associates eTrust Intrusion Detection Solutions & Patches
http://supportconnectw.ca.com/premium/etrust/etrust_intrusion/download s/eid-solpatch_r30.asp
Computer Associates eTrust Intrusion Detection 1.4.5
-
Computer Associates eTrust Intrusion Detection Solutions & Patches
http://supportconnectw.ca.com/premium/etrust/etrust_intrusion/download s/eid-solpatch_r30.asp
Computer Associates eTrust Intrusion Detection 1.5
-
Computer Associates eTrust Intrusion Detection Solutions & Patches
http://supportconnectw.ca.com/premium/etrust/etrust_intrusion/download s/eid-solpatch_r30.asp
Mandriva Linux Mandrake 10.1
-
Mandrake perl-Archive-Zip-1.14-1.0.101mdk.noarch.rpm
Mandrake Linux 10.1 & 10.1/X86_64
http://www.mandrakesecure.net/en/ftp.php
Mandriva Linux Mandrake 10.1 x86_64
-
Mandrake perl-Archive-Zip-1.14-1.0.101mdk.noarch.rpm
Mandrake Linux 10.1 & 10.1/X86_64
http://www.mandrakesecure.net/en/ftp.php
Computer Associates eTrust EZ Armor 2.0
-
Computer Associates eTrust EZ Antivirus - Arclib.dll Zip File Vulnerability
http://crm.my-etrust.com/CIDocument.asp?KDId=2220&GUID=E5BF5D4D1D6F40C 9B5C098F56E5CF221
Computer Associates eTrust EZ Armor 2.3
-
Computer Associates eTrust EZ Antivirus - Arclib.dll Zip File Vulnerability
http://crm.my-etrust.com/CIDocument.asp?KDId=2220&GUID=E5BF5D4D1D6F40C 9B5C098F56E5CF221
Computer Associates eTrust EZ Armor 2.4
-
Computer Associates eTrust EZ Antivirus - Arclib.dll Zip File Vulnerability
http://crm.my-etrust.com/CIDocument.asp?KDId=2220&GUID=E5BF5D4D1D6F40C 9B5C098F56E5CF221
McAfee Antivirus Engine 4.3.20
-
McAfee Antivirus Engine DATS 4398
For home (retail) users.
http://download.mcafee.com/uk/updates/updates.asp -
McAfee Antivirus Engine DATS 4398
For business (enterprise) users.
http://www.mcafeesecurity.com/uk/downloads/updates/dat.asp?id=1
Computer Associates InoculateIT 6.0
-
Computer Associates eTrust Antivirus 6.0 for Windows NT/2000/XP Solutions & Patches
http://supportconnectw.ca.com/premium/antivirus/downloads/nt/6.0/etavn t_60.asp
Computer Associates eTrust EZ Antivirus 6.1
-
Computer Associates eTrust EZ Antivirus - Arclib.dll Zip File Vulnerability
http://crm.my-etrust.com/CIDocument.asp?KDId=2220&GUID=E5BF5D4D1D6F40C 9B5C098F56E5CF221
Computer Associates eTrust EZ Antivirus 6.2
-
Computer Associates eTrust EZ Antivirus - Arclib.dll Zip File Vulnerability
http://crm.my-etrust.com/CIDocument.asp?KDId=2220&GUID=E5BF5D4D1D6F40C 9B5C098F56E5CF221
Computer Associates eTrust EZ Antivirus 6.3
-
Computer Associates eTrust EZ Antivirus - Arclib.dll Zip File Vulnerability
http://crm.my-etrust.com/CIDocument.asp?KDId=2220&GUID=E5BF5D4D1D6F40C 9B5C098F56E5CF221
Computer Associates eTrust Antivirus for the Gateway 7.0
-
Computer Associates eTrust Antivirus 7.0 for Gateway Solutions & Patches
http://supportconnectw.ca.com/premium/antivirus/downloads/gateway/etav gateway_70.asp
Computer Associates eTrust Antivirus 7.0
-
Computer Associates eTrust Antivirus 7 for Windows NT/2000/XP Solutions & Patches
http://supportconnectw.ca.com/premium/antivirus/downloads/nt/7.0/etavw innt_70.asp
Computer Associates eTrust Antivirus 7.1
-
Computer Associates eTrust Antivirus 7.1 for Windows NT/2000/XP Solutions & Patches
http://supportconnectw.ca.com/premium/antivirus/downloads/nt/7.1/etavw innt_71.asp
Computer Associates eTrust Antivirus for the Gateway 7.1
-
Computer Associates eTrust Antivirus 7.1 for Gateway Solutions & Patches
http://supportconnectw.ca.com/premium/antivirus/downloads/gateway/etav gateway_71.asp
References
Multiple Vendor Antivirus Software Zip Files Detection Evasion Vulnerability
References:
References:
- Anti-Virus Updates (McAfee)
- Eset NOD32 Homepage (ESET)
- Kaspersky Antivirus Homepage (Kaspersky Labs)
- RAV AntiVirus Homepage (RAV AntiVirus)
- Sophos Homepage (Sophos)
- Zip Evasion Vulnerability (Computer Associates)
- iDEFENSE Security Advisory 10.18.04: Multiple Vendor Anti-Virus Software ("customer service mailbox"
)