PT-2005-4170 · Avg · Avg 7
Andrey Bayora
·
Publicado
2005-10-29
·
Atualizado
2016-10-18
·
CVE-2005-3371
CVSS v2.0
5.1
Média
| Vetor | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AVG 7 version 7.0.323
Description
The issue allows remote attackers to bypass virus scanning by exploiting a multiple interpretation error. This can be achieved through files with an "MZ" magic byte sequence, typically associated with EXE files, but also present in files like BAT, HTML, and EML. Such files can be treated as safe types but still executed as dangerous file types by applications on the end system. An example of exploitation is a "triple headed" program containing EXE, EML, and HTML content.
Recommendations
For AVG 7 version 7.0.323, consider updating to a newer version that addresses this issue, as the current version allows for the bypassing of virus scanning through specific file types.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Avg 7