#1
SOFTWARE: eTrust Antivirus 7.x for Windows NT/2000/XP
DESCRIPTION: A vulnerability has been reported in eTrust Antivirus 7.0, allowing malware to bypass the virus detection.
The scanning engine doesn't handle ZIP archives containing password protected files correctly. The problem is that the scanning engine doesn't scan remaining files after a password protected file has been scanned, which allows an infected file to pass undetected.
Anmerkung: Wenn ich das richtig verstehe, bricht der Virenscanner, nachdem er ein passwortgeschütztes ZipFile gescannt hat, den Scanvorgang ab. Er meldet aber wohl : Alles gescannt Rechner Clean.
eTrust Antivirus 7.x for Windows NT/2000/XP
DESCRIPTION:
A vulnerability has been reported in eTrust Antivirus 7.0, allowing
malware to bypass the virus detection.
The scanning engine doesn't handle ZIP archives containing password
protected files correctly. The problem is that the scanning engine
doesn't scan remaining files after a password protected file has been
scanned, which allows an infected file to pass undetected.
SOLUTION:
Apply patch for 0302 level (Build 139) or higher.
ftp://ftp.ca.com/pub/unicenter/eTrust/AntiVirus/7.0/nt/qo50563/QO50563.exe
ftp://ftp.ca.com/pub/unicenter/eTrust/AntiVirus/7.0/nt/qo50563/QO50563.CAZ
Anmerkung:
Wenn ich das richtig verstehe, bricht der Virenscanner, nachdem er ein passwortgeschütztes ZipFile gescannt hat, den Scanvorgang ab.
Er meldet aber wohl : Alles gescannt Rechner Clean.
Das ist ein ziemlicher Hammer. Dem Ding würde ich nicht mehr vertrauen.
Wer den Scanner benutzt, sofort updaten.
__________
http://www.downclockers.com/ourforum/index.php?board=71.0 Reverse Engineering Malware