Summary
This host is installed with McAfee products and are prone to Security Bypass vulnerability.
Impact
Successful exploitation will allow attackers to bypass the anti-virus scanning and distribute files containing malicious code that the antivirus application will fail to detect.
Impact Level: System/Application
Solution
Updates are available through DAT files 5600 or later http://www.mcafee.com/apps/downloads/security_updates/dat.asp
Insight
Error in AV Engine fails to handle specially crafted packets via, - an invalid Headflags and Packsize fields in a malformed RAR archive.
- an invalid Filelength field in a malformed ZIP archive.
Affected
McAfee VirusScan
McAfee Email Gateyway
McAfee Total Protection
McAfee Active VirusScan
McAfee Internet Security
McAfee Security for Email Servers
McAfee Security for Microsoft Sharepoint
McAfee SecurityShield for Microsoft ISA Server
McAfee software that uses DAT files prior to 5600 on Windows
References
Severity
Classification
-
CVE CVE-2009-1348 -
CVSS Base Score: 7.6
AV:N/AC:H/Au:N/C:C/I:C/A:C
Related Vulnerabilities