PT-2008-6603 · Sunbelt · Sunbelt Vipre

Xhakerman2006

·

Published

2008-12-12

·

Updated

2018-10-11

·

CVE-2008-5542

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sunbelt VIPRE versions 3.1.1633.1 through 3.1.1832.2
Description The issue allows remote attackers to bypass malware detection in HTML documents by modifying the file header and extension. This can be achieved by placing an MZ header at the beginning of the file and changing the filename to have no extension, a .txt extension, or a .jpg extension. This technique can be used to bypass detection of exploits, such as the one demonstrated for a specific vulnerability.
Recommendations For Sunbelt VIPRE version 3.1.1633.1, update to a version that is not affected by this issue. For Sunbelt VIPRE version 3.1.1832.2, update to a version that is not affected by this issue. As a temporary workaround, consider restricting the processing of files with modified headers and extensions to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-5542

Affected Products

Sunbelt Vipre