Lucene search

K
cveMitreCVE-2009-1784
HistoryMay 22, 2009 - 8:30 p.m.

CVE-2009-1784

2009-05-2220:30:00
CWE-20
mitre
web.nvd.nist.gov
34
avg
parsing engine
bypass
malware detection
vulnerability
cve-2009-1784

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.6

Confidence

Low

EPSS

0.007

Percentile

80.3%

The AVG parsing engine 8.5 323, as used in multiple AVG anti-virus products including Anti-Virus Network Edition, Internet Security Netzwerk Edition, Server Edition für Linux/FreeBSD, Anti-Virus SBS Edition, and others allows remote attackers to bypass malware detection via a crafted (1) RAR and (2) ZIP archive.

Affected configurations

Nvd
Node
avgavg_anti-virusRange8.0.156
OR
avgavg_anti-virusMatch6.0.710
OR
avgavg_anti-virusMatch7.0
OR
avgavg_anti-virusMatch7.0.251
OR
avgavg_anti-virusMatch7.0.323
OR
avgavg_anti-virusMatch7.1.308
OR
avgavg_anti-virusMatch7.1.407
OR
avgavg_anti-virusMatch7.5.51
OR
avgavg_anti-virusMatch7.5.448
OR
avgavg_anti-virusMatch7.5.476
OR
avgavg_anti-virusMatch8.0
VendorProductVersionCPE
avgavg_anti-virus*cpe:2.3:a:avg:avg_anti-virus:*:*:*:*:*:*:*:*
avgavg_anti-virus6.0.710cpe:2.3:a:avg:avg_anti-virus:6.0.710:*:*:*:*:*:*:*
avgavg_anti-virus7.0cpe:2.3:a:avg:avg_anti-virus:7.0:*:*:*:*:*:*:*
avgavg_anti-virus7.0.251cpe:2.3:a:avg:avg_anti-virus:7.0.251:*:*:*:*:*:*:*
avgavg_anti-virus7.0.323cpe:2.3:a:avg:avg_anti-virus:7.0.323:*:*:*:*:*:*:*
avgavg_anti-virus7.1.308cpe:2.3:a:avg:avg_anti-virus:7.1.308:*:*:*:*:*:*:*
avgavg_anti-virus7.1.407cpe:2.3:a:avg:avg_anti-virus:7.1.407:*:*:*:*:*:*:*
avgavg_anti-virus7.5.51cpe:2.3:a:avg:avg_anti-virus:7.5.51:*:*:*:*:*:*:*
avgavg_anti-virus7.5.448cpe:2.3:a:avg:avg_anti-virus:7.5.448:*:*:*:*:*:*:*
avgavg_anti-virus7.5.476cpe:2.3:a:avg:avg_anti-virus:7.5.476:*:*:*:*:*:*:*
Rows per page:
1-10 of 111

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.6

Confidence

Low

EPSS

0.007

Percentile

80.3%

Related for CVE-2009-1784