Vulnerabilities > CVE-2010-1425 - Unspecified vulnerability in F-Secure products
Summary
F-Secure Internet Security 2010 and earlier; Anti-Virus for Microsoft Exchange 9 and earlier, and for MIMEsweeper 5.61 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, and for Linux 4.02 and earlier; Anti-Virus 2010 and earlier; Home Server Security 2009; Protection Service for Consumers 9 and earlier, for Business - Workstation security 9 and earlier, for Business - Server Security 8 and earlier, and for E-mail and Server security 9 and earlier; Mac Protection build 8060 and earlier; Client Security 9 and earlier; and various Anti-Virus products for Windows, Linux, and Citrix; does not properly detect malware in crafted (1) 7Z, (2) GZIP, (3) CAB, or (4) RAR archives, which makes it easier for remote attackers to avoid detection.
Vulnerable Configurations
Nessus
NASL family | Windows |
NASL id | FSECURE_FSC_2010_01.NASL |
description | The remote host has an antivirus product from F-Secure installed. According to its version, the product fails to accurately scan specially crafted 7Z, GZIP, CAB, and RAR archive files. It is, therefore, possible for such files to evade detection from the scanning engine. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 45528 |
published | 2010-04-14 |
reporter | This script is Copyright (C) 2010-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/45528 |
title | F-Secure Products Archive Files Scan Evasion (2010-1) |
code |
|
References
- http://secunia.com/advisories/39396
- http://secunia.com/advisories/39396
- http://www.f-secure.com/en_EMEA/support/security-advisory/fsc-2010-1.html
- http://www.f-secure.com/en_EMEA/support/security-advisory/fsc-2010-1.html
- http://www.securitytracker.com/id?1023841
- http://www.securitytracker.com/id?1023841
- http://www.securitytracker.com/id?1023842
- http://www.securitytracker.com/id?1023842
- http://www.securitytracker.com/id?1023843
- http://www.securitytracker.com/id?1023843
- http://www.vupen.com/english/advisories/2010/0855
- http://www.vupen.com/english/advisories/2010/0855