Symantec AntiVirus For Handhelds Scanning Bypass Vulnerability
BID:8640
Info
Symantec AntiVirus For Handhelds Scanning Bypass Vulnerability
| Bugtraq ID: | 8640 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 17 2003 12:00AM |
| Updated: | Sep 17 2003 12:00AM |
| Credit: | Discovery is credited to <[email protected]>. |
| Vulnerable: |
Symantec AntiVirus for Handhelds 3.0 .0.194 |
| Not Vulnerable: | |
Discussion
Symantec AntiVirus For Handhelds Scanning Bypass Vulnerability
The Symantec AntiVirus For Handhelds scanning engine may fail to detect variations of malicious code that definitions or heuristic detections exist for. The discoverer of this vulnerability tested the issue on the EICAR test virus. Reportedly, it is possible to bypass the scanner by adding a few random bytes of data before and after the test string.
This BID is being retired. The EICAR test file should not be detected if it has been modified, as stated at http://www.eicar.org/anti_virus_test_file.htm:
"The first 68 characters is the known string. It may be optionally appended by any combination of whitespace characters with the total file length not exceeding 128 characters. The only whitespace characters allowed are the space character, tab, LF, CR, CTRL-Z. To keep things simple the file uses only upper case letters, digits and punctuation marks, and does not include spaces. The only thing to watch out for when typing in the test file is that the third character is the capital letter "O", not the digit zero."
The Symantec AntiVirus For Handhelds scanning engine may fail to detect variations of malicious code that definitions or heuristic detections exist for. The discoverer of this vulnerability tested the issue on the EICAR test virus. Reportedly, it is possible to bypass the scanner by adding a few random bytes of data before and after the test string.
This BID is being retired. The EICAR test file should not be detected if it has been modified, as stated at http://www.eicar.org/anti_virus_test_file.htm:
"The first 68 characters is the known string. It may be optionally appended by any combination of whitespace characters with the total file length not exceeding 128 characters. The only whitespace characters allowed are the space character, tab, LF, CR, CTRL-Z. To keep things simple the file uses only upper case letters, digits and punctuation marks, and does not include spaces. The only thing to watch out for when typing in the test file is that the third character is the capital letter "O", not the digit zero."
Exploit / POC
Symantec AntiVirus For Handhelds Scanning Bypass Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Symantec AntiVirus For Handhelds Scanning Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Symantec AntiVirus For Handhelds Scanning Bypass Vulnerability
References:
References:
- Symantec AntiVirus for Handhelds Homepage (Symantec)
- The Anti-Virus test file (EICAR)
- Re: [Full-Disclosure] Exploiting Multiple Flaws in Symantec Antivirus 2004 for W (Sym Security
)