Multiple Vendor Anti-Virus Magic Byte Detection Evasion Vulnerability

BID:15189

Info

Multiple Vendor Anti-Virus Magic Byte Detection Evasion Vulnerability

Bugtraq ID: 15189
Class: Failure to Handle Exceptional Conditions
CVE: CVE-2005-3382
CVE-2005-3381
CVE-2005-3380
CVE-2005-3379
CVE-2005-3377
CVE-2005-3376
CVE-2005-3375
CVE-2005-3374
CVE-2005-3373
CVE-2005-3372
CVE-2005-3371
CVE-2005-3370
CVE-2005-3378
CVE-2005-3378
CVE-2005-3378
CVE-2005-3378
CVE-2005-3378
CVE-2005-3378
CVE-2005-3378
CVE-2005-3378
CVE-2005-3378
CVE-2005-3378
CVE-2005-3378
CVE-2005-3375
CVE-2005-3370
CVE-2005-3373
CVE-2005-3377
CVE-2005-3372
CVE-2005-3380
CVE-2005-3381
CVE-2005-3374
CVE-2005-3379
CVE-2005-3382
CVE-2005-3376
CVE-2005-3371
Remote: Yes
Local: No
Published: Oct 25 2005 12:00AM
Updated: Mar 19 2015 09:26AM
Credit: Wayne Langlois and Andrey Bayora are credited with the discovery of this vulnerability.
Vulnerable: Ukranian National Antivirus UNA
Trend Micro PC-cillin 2005
Trend Micro OfficeScan Corporate Edition 7.0
TheHacker TheHacker Antivirus 5.8.4 .128
Sophos Anti-Virus 3.91
Panda Titanium
Norman Virus Control 5.81
McAfee VirusScan Enterprise 8.0
McAfee Internet Security Suite 7.1.5
Kaspersky Labs Anti-Virus 5.0.372
Ikarus Ikarus 2.32
Frisk Software F-Prot Antivirus 3.16 c
Fortinet Antivirus 2.48 .0.0
eTrust eTrust CA 7.0.14
Dr.Web Dr.Web 4.32 b
Cat Computer Services Quick Heal Antivirus 8.0
AVG AVG Anti-Virus 7.0.323
ArcaBit ArcaVir 2005.0
Not Vulnerable: VirusBlokAda VBA32
Trend Micro PC-cillin 2006
Symantec Norton Internet Security 2005 11.5.6 .14
Symantec AntiVirus Corporate Edition 10.0
Sophos Anti-Virus 5.0.2
Sophos Anti-Virus 3.95
Softwin BitDefender 8.0
NOD32 NOD32 2.50.25
H+BEDV AntiVir Personal 6.31 .00.01
F-Secure Anti-Virus 5.56
ClamWin ClamWin 0.86.1
Avast! Antivirus Home Edition 4.6.655

Discussion

Multiple Vendor Anti-Virus Magic Byte Detection Evasion Vulnerability

Multiple vendor anti-virus software is prone to a detection evasion vulnerability.

The problem presents itself in the way various anti-virus software determines the type of file it is scanning.

An attacker can exploit this vulnerability to pass malicious files passed the anti-virus software. This results in a false sense of security, and ultimately could lead to the execution of arbitrary code on the victim user's machine.

Exploit / POC

Multiple Vendor Anti-Virus Magic Byte Detection Evasion Vulnerability

The discoverer of this issue has supplied the following proof of concept demonstrating this issue:
http://www.securityelf.org/magicbyte.html

Solution / Fix

Multiple Vendor Anti-Virus Magic Byte Detection Evasion Vulnerability

Solution:
Trend Micro PC-cillin 2006 is not affected by this issue. Please contact the vendor to obtain fixes.

Kaspersky Labs states that a fix for all affected versions of Kaspersky Labs Anti-Virus was made available as of 11 November, 2005. This fix is available through the normal signature update functionality.

References

Multiple Vendor Anti-Virus Magic Byte Detection Evasion Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report