7.6
CVE-2009-1348
- EPSS 2.84%
- Veröffentlicht 30.04.2009 20:30:00
- Zuletzt bearbeitet 16.06.2026 23:07:05
- Erkennungen
The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Email Servers, Email Gateway, and Active Virus Defense allows remote attackers to bypass virus detection via (1) an invalid Headflags field in a malformed RAR archive, (2) an invalid Packsize field in a malformed RAR archive, or (3) an invalid Filelength field in a malformed ZIP archive.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mcafee ≫ Internet Security Suite Version 2004
Mcafee ≫ Internet Security Suite Version 2005
Mcafee ≫ Internet Security Suite Version 2006
Mcafee ≫ Internet Security Suite Version 2009
Mcafee ≫ Total Protection Version 2009
Mcafee ≫ Virusscan Enterprise Version - Update - Edition linux
Mcafee ≫ Virusscan Enterprise Version - Update - Edition sap
Mcafee ≫ Virusscan Enterprise Version - Update - Edition storage
Mcafee ≫ Virusscan Plus Version 2009
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.84% | 0.848 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.6 | 4.9 | 10 |
AV:N/AC:H/Au:N/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://blog.zoller.lu/2009/04/mcafee-multiple-bypassesevasions-ziprar.html
http://secunia.com/advisories/34949
http://www.securityfocus.com/archive/1/503173/100/0/threaded
http://www.securityfocus.com/bid/34780
https://kc.mcafee.com/corporate/index?page=content&id=SB10001&actp=LIST_RECENT