F-Prot Antivirus ZIP Attachment Version Scan Evasion Vulnerability
BID:15293
Info
F-Prot Antivirus ZIP Attachment Version Scan Evasion Vulnerability
| Bugtraq ID: | 15293 |
| Class: | Design Error |
| CVE: |
CVE-2005-3499 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 2005 12:00AM |
| Updated: | Apr 02 2009 07:26PM |
| Credit: | Thierry Zoller <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
Sybari Antigen for Exchange 7.5.1314 Softwin BitDefender 7.0 McAfee VirusScan 4.5.1 McAfee VirusScan 4.5 McAfee VirusScan 4.0.3 McAfee VirusScan 4.0 H+BEDV AntiVir Windows Workstation 6.30 .0.5 Frisk Software F-Prot Antivirus for Windows Frisk Software F-Prot Antivirus for Solaris Frisk Software F-Prot Antivirus for Linux Workstation 4.6.8 Frisk Software F-Prot Antivirus for Linux and BSD 4.4.2 Frisk Software F-Prot Antivirus for Linux and BSD 3.12 d Frisk Software F-Prot Antivirus for Linux and BSD 3.12 b Frisk Software F-Prot Antivirus for Linux Frisk Software F-Prot Antivirus for Exchange Frisk Software F-Prot Antivirus for BSD Frisk Software F-Prot Antivirus Engine 4.4.4 Frisk Software F-Prot Antivirus Engine 0 Frisk Software F-Prot Antivirus 6.2.1 .4252 Frisk Software F-Prot Antivirus 6.0.9 .0 Frisk Software F-Prot Antivirus 4.6.7 Frisk Software F-Prot Antivirus 4.6.6 Frisk Software F-Prot Antivirus 3.16 c Frisk Software F-Prot Antivirus 3.16f AVG AVG Anti-Virus 7.1.308 |
| Not Vulnerable: | |
Discussion
F-Prot Antivirus ZIP Attachment Version Scan Evasion Vulnerability
F-prot Antivirus is prone to a scan-evasion vulnerability when dealing with ZIP archive attachments. This issue stems from a design error in the application, which flags certain ZIP files as harmless when it can't decompress them.
An attacker can exploit this vulnerability by crafting a specially designed ZIP file containing malicious code that will bypass the antivirus software.
F-prot Antivirus is prone to a scan-evasion vulnerability when dealing with ZIP archive attachments. This issue stems from a design error in the application, which flags certain ZIP files as harmless when it can't decompress them.
An attacker can exploit this vulnerability by crafting a specially designed ZIP file containing malicious code that will bypass the antivirus software.
Exploit / POC
F-Prot Antivirus ZIP Attachment Version Scan Evasion Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
F-Prot Antivirus ZIP Attachment Version Scan Evasion Vulnerability
Solution:
Reports indicate that the vendor will be addressing this issue in an upcoming version, but Symantec has not confirmed this.
Solution:
Reports indicate that the vendor will be addressing this issue in an upcoming version, but Symantec has not confirmed this.
References
F-Prot Antivirus ZIP Attachment Version Scan Evasion Vulnerability
References:
References:
- AVG Anti-Virus Homepage (AVG)
- F-prot Product Page (Frisk Software)
- Home Page (Sybari)
- Home Page (BitDefender)
- McAfee Homepage (McAfee)
- Multiple AV Vendor Incorrect CRC32 Bypass Vulnerability. (Bipin Gautam)
- Vendor Homepage (H+BEDV)
- [ TZO-012005 ] F-Prot/Frisk Anti Virus bypass - ZIP Version Header (Thierry Zoller
) - Re: Multiple AV Vendor Incorrect CRC32 Bypass Vulnerability. ([email protected])