Multiple Vendor Anti-Virus Magic Byte Detection Evasion Vulnerability
BID:15189
Info
Multiple Vendor Anti-Virus Magic Byte Detection Evasion Vulnerability
| Bugtraq ID: | 15189 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2005-3382 CVE-2005-3381 CVE-2005-3380 CVE-2005-3379 CVE-2005-3377 CVE-2005-3376 CVE-2005-3375 CVE-2005-3374 CVE-2005-3373 CVE-2005-3372 CVE-2005-3371 CVE-2005-3370 CVE-2005-3378 CVE-2005-3378 CVE-2005-3378 CVE-2005-3378 CVE-2005-3378 CVE-2005-3378 CVE-2005-3378 CVE-2005-3378 CVE-2005-3378 CVE-2005-3378 CVE-2005-3378 CVE-2005-3375 CVE-2005-3370 CVE-2005-3373 CVE-2005-3377 CVE-2005-3372 CVE-2005-3380 CVE-2005-3381 CVE-2005-3374 CVE-2005-3379 CVE-2005-3382 CVE-2005-3376 CVE-2005-3371 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 25 2005 12:00AM |
| Updated: | Mar 19 2015 09:26AM |
| Credit: | Wayne Langlois and Andrey Bayora are credited with the discovery of this vulnerability. |
| Vulnerable: |
Ukranian National Antivirus UNA Trend Micro PC-cillin 2005 Trend Micro OfficeScan Corporate Edition 7.0 TheHacker TheHacker Antivirus 5.8.4 .128 Sophos Anti-Virus 3.91 Panda Titanium Norman Virus Control 5.81 McAfee VirusScan Enterprise 8.0 McAfee Internet Security Suite 7.1.5 Kaspersky Labs Anti-Virus 5.0.372 Ikarus Ikarus 2.32 Frisk Software F-Prot Antivirus 3.16 c Fortinet Antivirus 2.48 .0.0 eTrust eTrust CA 7.0.14 Dr.Web Dr.Web 4.32 b Cat Computer Services Quick Heal Antivirus 8.0 AVG AVG Anti-Virus 7.0.323 ArcaBit ArcaVir 2005.0 |
| Not Vulnerable: |
VirusBlokAda VBA32 Trend Micro PC-cillin 2006 Symantec Norton Internet Security 2005 11.5.6 .14 Symantec AntiVirus Corporate Edition 10.0 Sophos Anti-Virus 5.0.2 Sophos Anti-Virus 3.95 Softwin BitDefender 8.0 NOD32 NOD32 2.50.25 H+BEDV AntiVir Personal 6.31 .00.01 F-Secure Anti-Virus 5.56 ClamWin ClamWin 0.86.1 Avast! Antivirus Home Edition 4.6.655 |
Discussion
Multiple Vendor Anti-Virus Magic Byte Detection Evasion Vulnerability
Multiple vendor anti-virus software is prone to a detection evasion vulnerability.
The problem presents itself in the way various anti-virus software determines the type of file it is scanning.
An attacker can exploit this vulnerability to pass malicious files passed the anti-virus software. This results in a false sense of security, and ultimately could lead to the execution of arbitrary code on the victim user's machine.
Multiple vendor anti-virus software is prone to a detection evasion vulnerability.
The problem presents itself in the way various anti-virus software determines the type of file it is scanning.
An attacker can exploit this vulnerability to pass malicious files passed the anti-virus software. This results in a false sense of security, and ultimately could lead to the execution of arbitrary code on the victim user's machine.
Exploit / POC
Multiple Vendor Anti-Virus Magic Byte Detection Evasion Vulnerability
The discoverer of this issue has supplied the following proof of concept demonstrating this issue:
http://www.securityelf.org/magicbyte.html
The discoverer of this issue has supplied the following proof of concept demonstrating this issue:
http://www.securityelf.org/magicbyte.html
Solution / Fix
Multiple Vendor Anti-Virus Magic Byte Detection Evasion Vulnerability
Solution:
Trend Micro PC-cillin 2006 is not affected by this issue. Please contact the vendor to obtain fixes.
Kaspersky Labs states that a fix for all affected versions of Kaspersky Labs Anti-Virus was made available as of 11 November, 2005. This fix is available through the normal signature update functionality.
Solution:
Trend Micro PC-cillin 2006 is not affected by this issue. Please contact the vendor to obtain fixes.
Kaspersky Labs states that a fix for all affected versions of Kaspersky Labs Anti-Virus was made available as of 11 November, 2005. This fix is available through the normal signature update functionality.
References
Multiple Vendor Anti-Virus Magic Byte Detection Evasion Vulnerability
References:
References:
- Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability through forg (Andrey Bayora)
- The Magic of magic byte (Andrey Bayora)
- Update for Magic Byte Bug (Andrey Bayora)
- Trend Micro's Response to the Magic Byte Bug (Auri Rahimzadeh
) - Update for the magic byte bug ("Andrey Bayora"
)