漏洞标题
N/A
漏洞描述信息
Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 允许远程攻击者通过修改 coffFiles 字段的 CAB 文件绕过 malware 检测。注意:如果发布额外的信息,表明不同的 CAB 解析器实现中该错误 independently 发生在,那么此错误可能会被 Split 成多个 CVE。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via a CAB file with a modified coffFiles field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
多个杀毒产品CAB文件权限许可和访问控制漏洞
漏洞描述信息
Dr.Web 5.0.2.03300版本,Trend Micro HouseCall 9.120.0.1004版本,Kaspersky Anti-Virus 7.0.0.125版本,Sophos Anti-Virus 4.61.0版本,Trend Micro AntiVirus 9.120.0.1004版本,McAfee Gateway (原为Webwasher) 2010.1C版本,Emsisoft Anti-Malware 5.1.0.1版本,CA eTrust Vet Antivirus 36.1.
CVSS信息
N/A
漏洞类别
授权问题