F-Secure Anti-Virus May Fail to Scan Certain ZIP and RAR Archives
|
|
SecurityTracker Alert ID: 1022170 |
|
SecurityTracker URL: http://securitytracker.com/id/1022170
|
|
CVE Reference:
CVE-2009-1782
(Links to External Site)
|
Updated: May 28 2009
|
Original Entry Date: May 6 2009
|
Impact:
Host/resource access via network, Modification of user information
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 2009 and prior; various other product versions
|
Description:
A vulnerability was reported in F-Secure Anti-Virus. A user can create an archive that will bypass detection.
A remote user can create a specially crafted ZIP or RAR archive that, when processed by the target user or application, will will not be detected by the scanning engine.
The following product versions are affected:
F-Secure Anti-Virus 2009 and prior
F-Secure Anti-Virus for Microsoft Exchange 7.10 and prior
F-Secure Anti-Virus for Workstations 8.0 and prior
F-Secure Anti-Virus Linux Client Security 5.54 and prior
F-Secure Anti-Virus for Windows Servers 8.00 and prior
F-Secure Anti-Virus for Citrix Servers 7.00 and prior
F-Secure Anti-Virus Linux Server Security 5.54 and prior
F-Secure Anti-Virus for Linux Servers 4.65
F-Secure Anti-Virus for MIMEsweeper 5.61 and prior
F-Secure Linux Security is also affected.
Roger Mickael reported this vulnerability.
|
Impact:
A user can create an archive that will bypass detection.
|
Solution:
The vendor has issued a fix. A patch matrix is available in the F-Secure advisory.
The vendor's advisory is available at:
http://www.f-secure.com/en_EMEA/support/security-advisory/fsc-2009-1.html
|
Vendor URL: www.f-secure.com/en_EMEA/support/security-advisory/fsc-2009-1.html (Links to External Site)
|
Cause:
State error
|
Underlying OS:
Linux (Any), Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Wed, 6 May 2009 15:20:14 -0400
Subject: F-Secure Anti-Virus, F-Secure Internet Gatekeeper, F-Secure Protection Service for Business, F-Secure Internet Security, F-Secure Client Security
|
http://www.f-secure.com/en_EMEA/support/security-advisory/fsc-2009-1.html
|
|