|
F-Secure
Security Bulletin FSC-2007-5
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Date issued |
2007-06-19 |
||||||||||||||||||||||||||||||||||||||
|
Last updated |
2007-06-18 |
||||||||||||||||||||||||||||||||||||||
|
Risk factor |
Medium (Low/Medium/High/Critical) |
||||||||||||||||||||||||||||||||||||||
|
Brief description |
Several F-Secure products are affected by archive file scan bypass vulnerabilities: - user decompressable, crafted RAR archives cannot be parsed (opened) by Anti-Virus - user decompressable, crafted LHA archives cannot be parsed (opened) by Anti-Virus |
||||||||||||||||||||||||||||||||||||||
|
Software |
F-Secure's Anti-Virus products for Microsoft Windows and Linux |
||||||||||||||||||||||||||||||||||||||
|
Affected versions |
F-Secure Anti-Virus for Workstations version 7.00 and
earlier |
||||||||||||||||||||||||||||||||||||||
|
Affected platforms |
All platforms supported by the affected products |
||||||||||||||||||||||||||||||||||||||
|
Bulletin
location |
http://www.f-secure.com/security/fsc-2007-5.shtml |
||||||||||||||||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||||||||||||||
|
Issue: |
An attacker may create a specially crafted LHA or RAR archive file with manipulated archive file header fields and malicious contents, which then goes through Anti-Virus scanning without interception. The manipulated file header fields basically break the archive file from Anti-Virus point of view, but certain decompression programs are still capable of opening archive for the user, in some cases with errors displayed. |
||||||||||||||||||||||||||||||||||||||
|
Workstation products: |
F-Secure Internet Security 2005, 2006 and 2007 F-Secure Client Security version 7.00 and earlier F-Secure Anti-Virus for Workstations 7.00 and earlier F-Secure Linux Client Security 5.52 and earlier |
||||||||||||||||||||||||||||||||||||||
|
Risk Factor: |
Low These products contain the described vulnerabilities, but do not scan inside archives by default, except by their possible e-mail scanning component. Archive contents that evade the detection in initial scanning, will be intercepted at the time of decompression. Recent antivirus database updates have automatically fixed both of the mentioned issues, without any intervention needed by the user/administrator. |
||||||||||||||||||||||||||||||||||||||
|
Server products: |
F-Secure Anti-Virus for Windows Servers 7.00 and earlier F-Secure Linux Server Security 5.52 and earlier |
||||||||||||||||||||||||||||||||||||||
|
Risk Factor: |
Low These products contain the described vulnerabilities, but do not scan inside archives by default. Recent antivirus database updates have automatically fixed both of the mentioned issues, without any intervention needed by the user/administrator. |
||||||||||||||||||||||||||||||||||||||
|
Gateway products: |
F-Secure Internet Gatekeeper 6.61 and earlier |
||||||||||||||||||||||||||||||||||||||
|
Risk Factor: |
High These gateway products typically scan inside archives, thus are affected by the vulnerability. However antivirus software on the receiving clients intercept the malicious contents at the point of archive decompression by the user. Recent antivirus database updates have automatically fixed both of the mentioned issues, without any intervention needed by the user/administrator. |
||||||||||||||||||||||||||||||||||||||
|
Gateways products: |
F-Secure Anti-Virus for MIMEsweeper 5.61 and earlier |
||||||||||||||||||||||||||||||||||||||
|
Risk Factor: |
Medium F-Secure Anti-Virus for MIMEsweeper does not handle archives. Archives are handled by MIMEsweeper and this vulnerability does not affect the reliability of such systems. The vulnerability does however affect the virus scanner's ability to detect malware that is stored in archives on the disk of the computer that runs MIMEsweeper. The impact of this is however minimal in the default configuration. Recent antivirus database updates have automatically fixed both of the mentioned issues, without any intervention needed by the user/administrator. |
||||||||||||||||||||||||||||||||||||||
|
Mitigating Factors: |
|
||||||||||||||||||||||||||||||||||||||
|
Patch availability: |
|
||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||
|
Credits: F-Secure wants to thank Thierry Zoller in n.runs AG (http://www.nruns.com/) for reporting these issues. |
|||||||||||||||||||||||||||||||||||||||
|
Revision History: |
FSC-2007-5 - 2007-06-15 |
||||||||||||||||||||||||||||||||||||||
|
|
|
||||||||||||||||||||||||||||||||||||||
Contact Information:
Support: http://support.f-secure.com/enu/home/contactus/
Security: http://www.f-secure.com/security/
URL: http://www.f-secure.com/