13263Third-party advisory
http://secunia.com/advisories/13263 CVE-2004-2442
Multiple AntiVirus - '.zip' Detection Bypass
Record summary
CVE-2004-2442 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Servers and Gateways 4.61 and earlier, and other products, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on the target system.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMultiple AntiVirus - '.zip' Detection BypassExploitDB exploitby oc192Not analyzed1 file
References
7P-041Third-party advisoryGovernment resource
http://www.ciac.org/ciac/bulletins/p-041.shtml f-secure.comConfirmation
http://www.f-secure.com/security/fsc-2004-3.shtml VU#968818Third-party advisory
http://www.kb.cert.org/vuls/id/968818 11732vdb entry
http://www.securityfocus.com/bid/11732 fsecure-zip-scan-bypass(18217)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/18217 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-2442