Author Topic: Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability  (Read 3115 times)

0 Members and 1 Guest are viewing this topic.

zaibatsu

  • Guest
iDEFENSE Security Advisory 10.18.04:

This vulnerability affects multiple anti-virus vendors including McAfee, Computer Associates, Kaspersky, Sophos, Eset and RAV.

II. DESCRIPTION

Remote exploitation of an exceptional condition error in multiple vendors’ anti-virus software allows attackers to bypass security protections by evading virus detection.

The problem specifically exists in the parsing of .zip archive headers. The .zip file format stores information about compressed files in two locations - a local header and a global header. The local header exists just before the compressed data of each file, and the global header exists at the end of the .zip archive. It is possible to modify the uncompressed size of archived files in both the local and global header without affecting functionality. This has been confirmed with both WinZip and Microsoft Compressed Folders. An attacker can compress a malicious payload and evade detection by some anti-virus software by modifying the uncompressed size within the local and global headers to zero.


Just wondering if Avast is covered for this threat

Reference:


h**p://www.idefense.com/application/poi/display?id=153&type=vulnerabilities

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re:Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability
« Reply #1 on: October 21, 2004, 08:44:26 PM »
Well from technical view, Home Edition doesn't have this vulnerability. At least not On-Access scanner which doesn't extract any archives. Scanning is done on default extraction (via WinZIP or any other utility).
ashQuick and On-Demand (only with Scan Archives checked option) are probably affected. Pro Edition is vulnerable only if you have archive scanning enabled for On-Access. Everything else is the same as for HE.
Visit my webpage Angry Sheep Blog

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability
« Reply #2 on: October 21, 2004, 08:45:20 PM »
This is already known to us and already handled in another thread. Please use the search function on this board prior to start a new (duplicate) thread.