MidnightBSD

Advisories for virusbuster

CVE-2010-5182 MEDIUM

Race condition in VirusBuster Internet Security Suite 3.2 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-362,

Products Affected

Vendor Product Version
virusbuster virusbuster_internet_securit_suite 3.2
CVE-2012-1423 MEDIUM

The TAR file parser in Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, K7 AntiVirus 9.77.3565, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
k7computing antivirus 9.77.3565
pc_tools pc_tools_antivirus 7.0.3.5
fortinet fortinet_antivirus 4.2.254.0
authentium command_antivirus 5.2.11.5
eset nod32_antivirus 5795
f-prot f-prot_antivirus 4.6.2.117
emsisoft anti-malware 5.1.0.1
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
norman norman_antivirus_&_antispyware 6.06.12
rising-global rising_antivirus 22.83.00.03
virusbuster virusbuster 13.6.151.0
CVE-2012-1443 MEDIUM

The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
avira antivir 7.11.1.163
microsoft security_essentials 2.0
ahnlab v3_internet_security 2011.01.18.00
sophos sophos_anti-virus 4.61.0
virusbuster virusbuster 13.6.151.0
comodo comodo_antivirus 7424
k7computing antivirus 9.77.3565
mcafee gateway 2010.1c
antiy avl_sdk 2.0.3.7
clamav clamav 0.96.4
pc_tools pc_tools_antivirus 7.0.3.5
jiangmin jiangmin_antivirus 13.0.900
mcafee scan_engine 5.400.0.1158
cat quick_heal 11.00
trendmicro housecall 9.120.0.1004
pandasecurity panda_antivirus 10.0.2.7
nprotect nprotect_antivirus 2011-01-17.01
gdata-software g_data_antivirus 21
kaspersky kaspersky_anti-virus 7.0.0.125
aladdin esafe 7.0.17.0
symantec endpoint_protection 11.0
authentium command_antivirus 5.2.11.5
avg avg_anti-virus 10.0.0.1190
bitdefender bitdefender 7.2
f-prot f-prot_antivirus 4.6.2.117
emsisoft anti-malware 5.1.0.1
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
rising-global rising_antivirus 22.83.00.03
alwil avast_antivirus 4.8.1351.0
trendmicro trend_micro_antivirus 9.120.0.1004
alwil avast_antivirus 5.0.677.0
f-secure f-secure_anti-virus 9.0.16160.0
fortinet fortinet_antivirus 4.2.254.0
anti-virus vba32 3.12.14.2
eset nod32_antivirus 5795
norman norman_antivirus_&_antispyware 6.06.12
CVE-2012-1457 MEDIUM

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
avira antivir 7.11.1.163
microsoft security_essentials 2.0
virusbuster virusbuster 13.6.151.0
k7computing antivirus 9.77.3565
mcafee gateway 2010.1c
antiy avl_sdk 2.0.3.7
clamav clamav 0.96.4
pc_tools pc_tools_antivirus 7.0.3.5
jiangmin jiangmin_antivirus 13.0.900
mcafee scan_engine 5.400.0.1158
cat quick_heal 11.00
trendmicro housecall 9.120.0.1004
gdata-software g_data_antivirus 21
kaspersky kaspersky_anti-virus 7.0.0.125
aladdin esafe 7.0.17.0
symantec endpoint_protection 11.0
authentium command_antivirus 5.2.11.5
avg avg_anti-virus 10.0.0.1190
bitdefender bitdefender 7.2
f-prot f-prot_antivirus 4.6.2.117
emsisoft anti-malware 5.1.0.1
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
rising-global rising_antivirus 22.83.00.03
alwil avast_antivirus 4.8.1351.0
trendmicro trend_micro_antivirus 9.120.0.1004
alwil avast_antivirus 5.0.677.0
anti-virus vba32 3.12.14.2
eset nod32_antivirus 5795
norman norman_antivirus_&_antispyware 6.06.12
CVE-2012-1459 MEDIUM

The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
avira antivir 7.11.1.163
microsoft security_essentials 2.0
ahnlab v3_internet_security 2011.01.18.00
sophos sophos_anti-virus 4.61.0
virusbuster virusbuster 13.6.151.0
comodo comodo_antivirus 7424
k7computing antivirus 9.77.3565
mcafee gateway 2010.1c
antiy avl_sdk 2.0.3.7
clamav clamav 0.96.4
pc_tools pc_tools_antivirus 7.0.3.5
jiangmin jiangmin_antivirus 13.0.900
mcafee scan_engine 5.400.0.1158
cat quick_heal 11.00
trendmicro housecall 9.120.0.1004
pandasecurity panda_antivirus 10.0.2.7
nprotect nprotect_antivirus 2011-01-17.01
gdata-software g_data_antivirus 21
kaspersky kaspersky_anti-virus 7.0.0.125
symantec endpoint_protection 11.0
authentium command_antivirus 5.2.11.5
avg avg_anti-virus 10.0.0.1190
bitdefender bitdefender 7.2
f-prot f-prot_antivirus 4.6.2.117
emsisoft anti-malware 5.1.0.1
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
rising-global rising_antivirus 22.83.00.03
alwil avast_antivirus 4.8.1351.0
trendmicro trend_micro_antivirus 9.120.0.1004
alwil avast_antivirus 5.0.677.0
f-secure f-secure_anti-virus 9.0.16160.0
fortinet fortinet_antivirus 4.2.254.0
anti-virus vba32 3.12.14.2
eset nod32_antivirus 5795
norman norman_antivirus_&_antispyware 6.06.12