HIGH · 7.6

CVE-2009-1348

The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Email Servers, Email Ga...

Vulnerability Description

The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Email Servers, Email Gateway, and Active Virus Defense allows remote attackers to bypass virus detection via (1) an invalid Headflags field in a malformed RAR archive, (2) an invalid Packsize field in a malformed RAR archive, or (3) an invalid Filelength field in a malformed ZIP archive.

CVSS Score

7.6

HIGH

AV:N/AC:H/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
McafeeActive Virus DefenseAll versions
McafeeActive VirusscanAll versions
McafeeEmail GatewayAll versions
McafeeInternet Security SuiteAll versions
McafeeSecurityshield For Email ServersAll versions
McafeeSecurityshield For Microsoft Isa ServerAll versions
McafeeSecurityshield For Microsoft SharepointAll versions
McafeeTotal Protection2009
McafeeTotal Protection For EndpointAll versions
McafeeVirusscan CommandlineAll versions
McafeeVirusscan EnterpriseAll versions
McafeeVirusscan Plus2009
McafeeVirusscan UsbAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-1348?

CVE-2009-1348 is a vulnerability with a CVSS score of 7.6 (HIGH). The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Email Servers, Email Ga...

How severe is CVE-2009-1348?

CVE-2009-1348 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-1348?

Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Active Virus Defense, Mcafee Active Virusscan, Mcafee Email Gateway, Mcafee Internet Security Suite, Mcafee Securityshield For Email Servers.