F-Secure Anti-Virus May Fail to Detect Malware in Various Archive Format Files
|
|
SecurityTracker Alert ID: 1023841 |
|
SecurityTracker URL: http://securitytracker.com/id/1023841
|
|
CVE Reference:
CVE-2010-1425
(Links to External Site)
|
Updated: Apr 20 2010
|
Original Entry Date: Apr 12 2010
|
Impact:
Host/resource access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 2010 and prior versions
|
Description:
A vulnerability was reported in F-Secure Anti-Virus. A remote user can bypass the anti-virus detection.
A remote user can create a specially crafted archive file containing malware that, when scanned by the target anti-virus engine, will not detect the enclosed malware.
The 7Z, GZIP, CAB, RAR archive formats are affected.
The following product versions are also affected:
F-Secure Anti-Virus Linux Client Security 5.54 and earlier
F-Secure Anti-Virus Linux Server Security 5.54 and earlier
F-Secure Anti-Virus for Linux Servers 4.65
F-Secure Anti-Virus for Citrix Servers 9 and earlier
F-Secure Anti-Virus for Workstations 9 and earlier
F-Secure Anti-Virus for Microsoft Exchange 9 and earlier
F-Secure Anti-Virus for MIMEsweeper 5.61 and earlier
ReversingLabs reported this vulnerability.
|
Impact:
A remote user can create content that will bypass the anti-virus detection mechanism.
|
Solution:
The vendor has issued a fix, available via the automatic update channel.
The following fixes are available for other product versions.
F-Secure Anti-Virus for Workstations 8 - 9: Automatic update channel
F-Secure Anti-Virus for Windows Servers 8 - 9: Automatic update channel
F-Secure Anti-Virus for Microsoft Exchange 9: Automatic update channel
F-Secure Anti-Virus for Citrix Servers 8 - 9: Automatic update channel
F-Secure Anti-Virus for Microsoft Exchange 6.62: ftp://ftp.f-secure.com/support/hotfix/fsav-mse/fsavmse662-10.zip
F-Secure Anti-Virus for Microsoft Exchange 7.10: ftp://ftp.f-secure.com/support/hotfix/fsav-mse/fsavmse710-06.zip
F-Secure Anti-Virus for Microsoft Exchange 8.00: ftp://ftp.f-secure.com/support/hotfix/fsav-mse/fsavmse800-03.zip
F-Secure Anti-Virus for Citrix Servers 7.00: ftp://ftp.f-secure.com/support/hotfix/fsav-server/FSAV744-11.fsfix
F-Secure Anti-Virus for MIMEsweeper 5.61: ftp://ftp.f-secure.com/support/hotfix/fsav-server/FSAVSR561-05.fsfix
The vendor's advisory is available at:
http://www.f-secure.com/en_EMEA/support/security-advisory/fsc-2010-1.html
|
Vendor URL: www.f-secure.com/en_EMEA/support/security-advisory/fsc-2010-1.html (Links to External Site)
|
Cause:
Input validation error, State error
|
Underlying OS:
Linux (Any), Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Mon, 12 Apr 2010 18:22:06 +0000
Subject: F-Secure Anti-Virus
|
http://www.f-secure.com/en_EMEA/support/security-advisory/fsc-2010-1.html
|
|