PT-2005-4170 · Avg · Avg 7

Andrey Bayora

·

Published

2005-10-29

·

Updated

2016-10-18

·

CVE-2005-3371

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AVG 7 version 7.0.323
Description The issue allows remote attackers to bypass virus scanning by exploiting a multiple interpretation error. This can be achieved through files with an "MZ" magic byte sequence, typically associated with EXE files, but also present in files like BAT, HTML, and EML. Such files can be treated as safe types but still executed as dangerous file types by applications on the end system. An example of exploitation is a "triple headed" program containing EXE, EML, and HTML content.
Recommendations For AVG 7 version 7.0.323, consider updating to a newer version that addresses this issue, as the current version allows for the bypassing of virus scanning through specific file types.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3371

Affected Products

Avg 7