Multiple Vendor Antivirus Products Obscured File Name Scan Evasion Vulnerability
BID:15423
Info
Multiple Vendor Antivirus Products Obscured File Name Scan Evasion Vulnerability
| Bugtraq ID: | 15423 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 15 2005 12:00AM |
| Updated: | Feb 20 2007 08:36PM |
| Credit: | [email protected] discovered this issue. |
| Vulnerable: |
Symantec AntiVirus Corporate Edition 8.0 RAV AntiVirus RAV AntiVirus Desktop 8.6 Microsoft AntiSpyware beta 1 Kaspersky Labs Anti-Virus Personal 4.5 .104 Kaspersky Labs Anti-Virus for Windows File Servers 4.5 .104 Frisk Software F-Prot Antivirus 3.16 c ClamWin ClamWin 0.87 Avast Antivirus Professional Edition 4.6.603 |
| Not Vulnerable: | |
Discussion
Multiple Vendor Antivirus Products Obscured File Name Scan Evasion Vulnerability
Multiple antivirus products from various vendors are reported prone to a vulnerability that may allow malicious files to bypass detection.
This issue arises when an affected application processes a file with an obscured name.
This issue could allow malicious files to bypass detection and to be opened by a recipient.
Update: Symantec is currently investigating this issue in Symantec products. It is unclear at this time if malicious files may evade scanning or if the automatic removal feature fails. This BID will be updated as more information is disclosed.
Multiple antivirus products from various vendors are reported prone to a vulnerability that may allow malicious files to bypass detection.
This issue arises when an affected application processes a file with an obscured name.
This issue could allow malicious files to bypass detection and to be opened by a recipient.
Update: Symantec is currently investigating this issue in Symantec products. It is unclear at this time if malicious files may evade scanning or if the automatic removal feature fails. This BID will be updated as more information is disclosed.
Exploit / POC
Multiple Vendor Antivirus Products Obscured File Name Scan Evasion Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Multiple Vendor Antivirus Products Obscured File Name Scan Evasion Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Multiple Vendor Antivirus Products Obscured File Name Scan Evasion Vulnerability
References:
References: