Die große Lücke mit den Archiven...?!? |
|
DerBilk
Lebende Legende
  

Dabei seit: 15.07.2005
Beiträge: 114
Level: 36 [?]
Erfahrungspunkte: 825.226
Nächster Level: 1.000.000
 |
|
|
09.10.2005 17:35 |
|
|
| |
|
DerBilk
Lebende Legende
  

Dabei seit: 15.07.2005
Beiträge: 114
Level: 36 [?]
Erfahrungspunkte: 825.226
Nächster Level: 1.000.000
Themenstarter
 |
|
Teil 2
Zitat: |
Norman Virus Control 5.0.0
Norman Virus Control 5.1.0
Norman Virus Control 5.2.0
Norman Virus Control 5.3.0
Norman Virus Control 5.4.0
Norman Virus Control 5.5.0
Norman Virus Control 5.7.0
Norman Virus Control for Exchange 2000 5.0.0
Norman Virus Control for Exchange 2000 5.1.0
Norman Virus Control for Exchange 2000 5.2.0
Norman Virus Control for Exchange 2000 5.3.0
Norman Virus Control for Exchange 2000 5.4.0
Norman Virus Control for Exchange 2000 5.5.0
Norman Virus Control for Exchange 5.5 5.0.0
Norman Virus Control for Exchange 5.5 5.1.0
Norman Virus Control for Exchange 5.5 5.2.0
Norman Virus Control for Exchange 5.5 5.3.0
Norman Virus Control for Exchange 5.5 5.4.0
Norman Virus Control for Exchange 5.5 5.5.0
Norman Virus Control for Firewall-1 5.0.0
Norman Virus Control for Firewall-1 5.1.0
Norman Virus Control for Firewall-1 5.2.0
Norman Virus Control for Firewall-1 5.3.0
Norman Virus Control for Firewall-1 5.4.0
Norman Virus Control for Firewall-1 5.5.0
Norman Virus Control for IIS 5.0.0
Norman Virus Control for IIS 5.1.0
Norman Virus Control for IIS 5.2.0
Norman Virus Control for IIS 5.3.0
Norman Virus Control for IIS 5.4.0
Norman Virus Control for IIS 5.5.0
Norman Virus Control for Linux 5.0.0
Norman Virus Control for Linux 5.1.0
Norman Virus Control for Linux 5.2.0
Norman Virus Control for Linux 5.3.0
Norman Virus Control for Linux 5.4.0
Norman Virus Control for Linux 5.5.0
Norman Virus Control for Lotus Domino 5.0.0
Norman Virus Control for Lotus Domino 5.1.0
Norman Virus Control for Lotus Domino 5.2.0
Norman Virus Control for Lotus Domino 5.3.0
Norman Virus Control for Lotus Domino 5.4.0
Norman Virus Control for Lotus Domino 5.5.0
Norman Virus Control for MIMESweeper 5.0.0
Norman Virus Control for MIMESweeper 5.1.0
Norman Virus Control for MIMESweeper 5.2.0
Norman Virus Control for MIMESweeper 5.3.0
Norman Virus Control for MIMESweeper 5.4.0
Norman Virus Control for MIMESweeper 5.5.0
Norman Virus Control for OS/2 5.0.0
Norman Virus Control for OS/2 5.1.0
Norman Virus Control for OS/2 5.2.0
Norman Virus Control for OS/2 5.3.0
Norman Virus Control for OS/2 5.4.0
Norman Virus Control for OS/2 5.5.0
Panda ActiveScan 5.0.0
Panda Antivirus for NetWare 2.0.0
Panda Antivirus Platinum 2.0.0
Softwin BitDefender
Softwin BitDefender 7.0.0
Softwin BitDefender 7.2.0
Softwin BitDefender 8.0.0
Softwin BitDefender 9.0.0
Softwin BitDefender Antivirus & Antispam for Linux 1.6.1
Softwin BitDefender Antivirus & Antispam for Linux 1.6.2
Sophos Anti-Virus 3.4.6
Sophos Anti-Virus 3.78.0
Sophos Anti-Virus 3.78.0 d
Sophos Anti-Virus 3.79.0
Sophos Anti-Virus 3.80.0
Sophos Anti-Virus 3.81.0
Sophos Anti-Virus 3.82.0
Sophos Anti-Virus 3.83.0
Sophos Anti-Virus 3.84.0
Sophos Anti-Virus 3.85.0
Sophos Anti-Virus 3.86.0
Sophos Anti-Virus 3.90.0
Sophos Anti-Virus 3.91.0
Sophos Anti-Virus 3.95.0
Sophos Anti-Virus 3.96.0 .0
Sophos Anti-Virus 4.5.3
Sophos Anti-Virus 4.5.4
Sophos Anti-Virus 5.0.1
Sophos Anti-Virus 5.0.4
Sophos Anti-Virus Engine 2.30.4
Symantec AntiVirus Corporate Edition 8.0.0
Symantec AntiVirus Corporate Edition 8.0.0 1
Symantec AntiVirus Corporate Edition 8.0.0 1.425a/b
Symantec AntiVirus Corporate Edition 8.0.0 1.429c
Symantec AntiVirus Corporate Edition 8.0.0 1.501
Symantec AntiVirus Corporate Edition 8.0.0 1.9374
Symantec AntiVirus Corporate Edition 8.0.0 1.9378
Symantec AntiVirus Corporate Edition 8.1.0
Symantec AntiVirus Corporate Edition 8.1.0 .0.825a
Symantec AntiVirus Corporate Edition 8.1.0 build 8.01.434
Symantec AntiVirus Corporate Edition 8.1.0 build 8.01.437
Symantec AntiVirus Corporate Edition 8.1.0 build 8.01.446
Symantec AntiVirus Corporate Edition 8.1.0 build 8.01.457
Symantec AntiVirus Corporate Edition 8.1.0 build 8.01.460
Symantec AntiVirus Corporate Edition 8.1.0 build 8.01.464
Symantec AntiVirus Corporate Edition 8.1.0 build 8.01.471
Symantec AntiVirus Corporate Edition 8.1.1
Symantec AntiVirus Corporate Edition 8.1.1 .366
Symantec AntiVirus Corporate Edition 8.1.1 build 8.1.1.314a
Symantec AntiVirus Corporate Edition 8.1.1 build 8.1.1.319
Symantec AntiVirus Corporate Edition 8.1.1 build 8.1.1.323
Symantec AntiVirus Corporate Edition 8.1.1 build 8.1.1.329
Symantec AntiVirus Corporate Edition 9.0.0
Symantec AntiVirus Corporate Edition 9.0.0 .0.338
Symantec AntiVirus Corporate Edition 9.0.1 .1.1000
Symantec AntiVirus Corporate Edition 9.0.2 .1000
Symantec AntiVirus Corporate Edition 9.0.3 .1000
Symantec AntiVirus Corporate Edition 9.0.4
Symantec AntiVirus Corporate Edition 10.0.0
Symantec AntiVirus for Caching
Symantec AntiVirus for Caching build 4.3.3
Symantec AntiVirus for Caching 4.3.3
Symantec AntiVirus for Handhelds 3.0.0
Symantec AntiVirus for Handhelds 3.0.0 .0.194
Symantec AntiVirus for Handhelds Corporate Edition 3.0.0
Symantec AntiVirus for Microsoft Exchange 2.18.0 build 82
Symantec AntiVirus for Microsoft Exchange 2.18.0 build 85
Symantec AntiVirus for Microsoft Exchange 2.18.0 build 88
Symantec AntiVirus for Microsoft Office
Symantec Antivirus for MS Office SharePoint Portal Server 2003
Symantec AntiVirus for Network Attached Storage
Symantec AntiVirus for SMTP 3.0.0 build 3.0.0.29
Symantec AntiVirus for SMTP 3.1.0
Symantec AntiVirus for SMTP 3.1.0 build 3.1.1
Symantec AntiVirus for SMTP 3.1.0 build 3.1.2
Symantec AntiVirus for SMTP 3.1.0 build 3.1.3
Symantec AntiVirus for SMTP 3.1.0 build 3.1.4
Symantec AntiVirus for SMTP 3.1.0 build 3.1.5
Symantec AntiVirus for SMTP 3.1.0 build 3.1.6
Symantec AntiVirus for SMTP 3.1.7
Symantec AntiVirus Scan Engine 4.0.0
Symantec AntiVirus Scan Engine 4.1.0
Symantec AntiVirus Scan Engine 4.3.0
Symantec AntiVirus Scan Engine 4.3.0 build 4.3.3
Symantec AntiVirus Scan Engine 4.3.0 build 4.3.7.27
Symantec AntiVirus Scan Engine 4.3.0 build 4.3.8.29
Symantec AntiVirus Scan Engine 4.3.3
Symantec AntiVirus Scan Engine 4.3.12
Symantec AntiVirus Scan Engine for Bluecoat 4.0.0
Symantec AntiVirus Scan Engine for Bluecoat 4.3.0
Symantec AntiVirus Scan Engine for Bluecoat 4.3.0 build 4.3.3
Symantec AntiVirus Scan Engine for Bluecoat 4.3.12
Symantec AntiVirus Scan Engine for Caching 4.3.0
Symantec AntiVirus Scan Engine for Caching 4.3.12
Symantec AntiVirus Scan Engine for Clearswift 4.0.0
Symantec AntiVirus Scan Engine for Clearswift 4.3.0
Symantec AntiVirus Scan Engine for Clearswift 4.3.12
Symantec AntiVirus Scan Engine for Filers 4.3.0
Symantec AntiVirus Scan Engine for Filers 4.3.0 build 4.3.3
Symantec AntiVirus Scan Engine for ISA 4.0.0
Symantec AntiVirus Scan Engine for ISA 4.3.0
Symantec AntiVirus Scan Engine for ISA 4.3.0 build 4.3.3
Symantec AntiVirus Scan Engine for ISA 4.3.12
Symantec AntiVirus Scan Engine for Messaging 4.3.0
Symantec AntiVirus Scan Engine for Messaging 4.3.12
Symantec AntiVirus Scan Engine for Microsoft Portal 4.3.0
Symantec AntiVirus Scan Engine for Microsoft SharePoint 4.3.0
Symantec AntiVirus Scan Engine for Microsoft SharePoint 4.3.12
Symantec AntiVirus Scan Engine for Netapp Filer 4.0.0
Symantec AntiVirus Scan Engine for Netapp Filer 4.3.0
Symantec AntiVirus Scan Engine for Netapp Filer 4.3.0 build 4.3.3
Symantec AntiVirus Scan Engine for Netapp Filer 4.3.12
Symantec AntiVirus Scan Engine for Netapp NetCache 4.0.0
Symantec AntiVirus Scan Engine for Netapp NetCache 4.3.0
Symantec AntiVirus Scan Engine for Netapp NetCache 4.3.0 build 4.3.3
Symantec AntiVirus Scan Engine for Netapp NetCache 4.3.12
Symantec AntiVirus Scan Engine for Network Attached Storage 4.3.0
Symantec AntiVirus Scan Engine for Network Attached Storage 4.3.12
Symantec AntiVirus Scan Engine for Red Hat Linux 4.0.0
Symantec AntiVirus Scan Engine for Red Hat Linux 4.3.0
Symantec AntiVirus/Filtering for Domino NT 3.1.0
Symantec AntiVirus/Filtering for Domino NT 3.1.0 build 3.1.1
Symantec AntiVirus/Filtering for Domino NT 3.1.1
Symantec AntiVirus/Filtering for Domino Ports 3.0.0
Symantec AntiVirus/Filtering for Domino Ports 3.0.0 (AIX) build 3.0.5
Symantec AntiVirus/Filtering for Domino Ports 3.0.0 (Linux) build 3.0.5
Symantec AntiVirus/Filtering for Domino Ports 3.0.0 (OS400) build 3.0.5
Symantec AntiVirus/Filtering for Domino Ports 3.0.0 (S390)
Symantec AntiVirus/Filtering for Domino Ports 3.0.0 (Solaris)build 3.0.5
Symantec AntiVirus/Filtering for Domino Ports 3.0.5
Symantec AntiVirus/Filtering for Domino Ports 3.0.6
Symantec AntiVirus/Filtering for Domino Ports 3.0.6 (AIX)
Symantec AntiVirus/Filtering for Domino Ports 3.0.7
Symantec AntiVirus/Filtering for Domino Ports 3.0.7 (Linux)
Symantec AntiVirus/Filtering for Domino Ports 3.0.7 (OS400)
Symantec AntiVirus/Filtering for Domino Ports 3.0.7 (Solaris)
Symantec Norton AntiVirus 2000
Symantec Norton AntiVirus 4.0.0 for NT
Symantec Norton AntiVirus 5.0.0
Symantec Norton AntiVirus 5.0.0 2
Symantec Norton AntiVirus 2001
Symantec Norton AntiVirus 2001 Professional Edition
Symantec Norton AntiVirus 2002
Symantec Norton AntiVirus 2002 Professional Edition
Symantec Norton Antivirus 2003
Symantec Norton AntiVirus 2003 Professional Edition
Symantec Norton AntiVirus 2004
Symantec Norton Antivirus 2004 for Macintosh
Symantec Norton AntiVirus 2004 Professional Edition
Symantec Norton AntiVirus 2005
Symantec Norton AntiVirus 2005 11.0.0
Symantec Norton Internet Security 2005
Symantec Norton Internet Security 2005 11.0.0
Symantec Norton System Works 2005 11.0.0
Symantec Norton AntiVirus 2005 11.0.9
Symantec Norton Internet Security 2005
Symantec Norton Internet Security 2005 11.0.9
Symantec Norton System Works 2005 Premier
Symantec Norton System Works 2005 11.0.9
Symantec Norton AntiVirus 2005 Professional Edition
Symantec Norton Antivirus 7.0 for Macintosh
Symantec Norton Antivirus 8.0 for Macintosh
Symantec Norton Antivirus 9.0 for Macintosh
Symantec Norton Antivirus 9.0 for Macintosh
Symantec Norton AntiVirus Corporate Edition 7.60.build 926
Symantec Norton AntiVirus Corporate Edition 7.0.0
Symantec Norton AntiVirus Corporate Edition 7.2.0
Symantec Norton AntiVirus Corporate Edition 7.5.0
Symantec Norton AntiVirus Corporate Edition 7.6.0
Symantec Norton AntiVirus Corporate Edition 7.51.0
Symantec Norton AntiVirus Corporate Edition 7.61.0
Symantec Norton AntiVirus Corporate Edition 8.0.0
Symantec Norton AntiVirus for Internet Email Gateways 1.0.0
Symantec Norton Antivirus for Macintosh Corporate Edition 9.0.0
Symantec Norton AntiVirus for Microsoft Exchange 2.18.0 build 83
Symantec Norton AntiVirus for MS Exchange 1.5.0
Symantec Norton AntiVirus for MS Exchange 2.0.0
Symantec Norton AntiVirus for MS Exchange 2.1.0
Symantec Norton AntiVirus for MS Exchange 2.5.0
Microsoft Exchange Server 2000
Microsoft Exchange Server 2000 SP1
Symantec Norton AntiVirus for MS Exchange 2.18.82
Symantec Norton AntiVirus for MS Exchange 2.18.85
Symantec Norton AntiVirus for MS Exchange 2.18.88
Symantec Norton AntiVirus for Windows ME 2001
Ukrainian Antiviral Center Ukrainian National Antivirus
VirusBlokAda VBA32
Short Summary
-------------
Multiple Vendor Antivirus Products fail to properly process certain
malformed archive files.
Impact
------
Malicious archives may bypass scanning by antivirus products.
Technical Description
---------------------
Multiple antivirus products from various vendors are reported prone to a
vulnerability that may allow malformed archives to bypass detection.
It is reported that various antivirus products do not properly identify
potentially malicious archives.
This issue arises when an affected application processes a specially
altered archive file that contains a fake, misleading header.
Specifically, the reporter of this issue created various test archives
(ARJ, RAR, CAB) containing the EICAR test file, and then modified the
resulting archive to contain a MS-DOS executable MZ header. The resulting
archives may still successfully be opened by certain decompression
programs, but are not properly scanned by multiple antivirus products.
The reporter of this issue states that the following archive types may be
vulnerable to similar alterations, leading to scan evasion:
- RAR
- ZIP
- CAB
- ARJ
- LZH
- ACE
- TAR
- GZ (GZIP)
- UUE
- BZ2
- JAR
- ISO
- 7Z
- Z
This issue could result in malicious archives bypassing detection and
allowing the contents to be opened by a recipient.
It should be noted that specific information regarding affected packages
and versions is currently unavailable. The reporter of this issue used
the EICAR test message stored in multiple different malformed archives.
It may be possible that some of the reportedly affected packages may
actually be immune to this issue.
This BID will be updated as further information is disclosed.
Attack Scenarios
----------------
To carry out an attack, the attacker crafts a malicious archive that
contains specifically altered header contents.
The attacker can send this archive through email to vulnerable users or
entice them to obtain the archive from a Web site or other means.
The malicious archive may evade antivirus scanning by the antivirus
scanners.
Users may then assume that the archive is safe and could interactively
execute its contents leading to a potential compromise.
(...) |
|
__________________ Gruß,
DerBilk
Nur weil ich paranoid bin, heisst das nicht, dass sie nicht hinter mir her sind... (Matthias Deutschmann)
|
|
09.10.2005 17:36 |
|
|
| |
|