Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2009-1784

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2009-1784
Last Modified 29 May 2009 12:00:00
Published 22 May 2009 04:30:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2009-1784

Summary

The AVG parsing engine 8.5 323, as used in multiple AVG anti-virus products including Anti-Virus Network Edition, Internet Security Netzwerk Edition, Server Edition für Linux/FreeBSD, Anti-Virus SBS Edition, and others allows remote attackers to bypass malware detection via a crafted (1) RAR and (2) ZIP archive.

Vulnerable Systems

Application

  • Avg Anti-virus 6.0.710

  • Avg Anti-virus 7.0

  • Avg Anti-virus 7.0.251

  • Avg Anti-virus 7.0.323

  • Avg Anti-virus 7.1.308

  • Avg Anti-virus 7.1.407

  • Avg Anti-virus 7.5.448

  • Avg Anti-virus 7.5.476

  • Avg Anti-virus 7.5.51

  • Avg Anti-virus 8.0

  • Avg Anti-virus 8.0.156


References

XF - avg-zip-security-bypass(50426)

BID - 34895

BUGTRAQ - 20090509 [TZO-20-2009] AVG ZIP evasion / bypass

MISC - http://blog.zoller.lu/2009/04/avg-zip-evasion-bypass.html


Last Updated: 27 May 2016 10:50:40