Author Topic: Does this problem exist in Avast?  (Read 3085 times)

0 Members and 1 Guest are viewing this topic.

jujubee

  • Guest
Does this problem exist in Avast?
« on: January 25, 2006, 02:14:35 AM »
Hi, I'm not sure if someone already mentioned this, but can someone tell me if the following problem exists in Avast! as well?

"Antivirus software vendor F-Secure issued a patch for a wide range of its products last Thursday after a security researcher in Luxembourg reported vulnerabilities to the company.

A flaw in the way F-Secure software handled ZIP and RAR format data compression archives could allow an attacker to execute remote code on users' systems and to bypass F-Secure's antivirus-scanning capabilities, according to Thierry Zoller, the security engineer and penetration tester who reported the vulnerability to F-Secure. F-Secure called the vulnerability "critical." "

"Zoller, on his blog, praised F-Secure for publicly fixing the vulnerability. "I found multiple vulnerabilities within various [antivirus] Engines, F-Secure are the first to actually publish a real advisory, others fixed the bugs silently or put a small notice in a change_log," he wrote.

Zoller said he will wait to publish details of the vulnerability. "There are too many [anitvirus] engines vulnerable and I am going to wait until most of them have patched the flaws until I exactly disclose my findings," he wrote."

Here's the link:

http://www.arnnet.com.au/index.php/id;1021392976;fp;2;fpid;1




Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48561
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Does this problem exist in Avast?
« Reply #1 on: January 25, 2006, 03:53:58 AM »
Hi jujubee,
Quote
Does this problem exist in Avast?
I sure hope not!!!
Hopefully someone from the Alwil team will post a reply.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re: Does this problem exist in Avast?
« Reply #2 on: January 25, 2006, 09:45:34 AM »
Since no details of this vulnerability are published, it's impossible to say for sure.
However, I am not aware of having been contacted by Mr. Zoller, so I'd guess avast! is safe.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Does this problem exist in Avast?
« Reply #3 on: January 25, 2006, 08:17:05 PM »
Hi igor,

What's known about this that this code execution vulnerability  is wrought through specially crafted ARJ packages with long filenames that will create a buffer overflow and remote control. Kav had similar problems in October last. It seems various scanners every few months or so had archive scanning troubles, and had to launch hotfixes. Good security means to deliver no zip or rar  file  that should be opened by any user unless they know the specific reason it's there and the exact source of the file. It mainly occurs where gateway installations scan web and mail traffic.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!