CVE-2008-5524: Input Validation
CAT-QuickHeal 10.00 and possibly 9.50, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5524?
CVE-2008-5524 is classified as a medium severity vulnerability due to its ability to bypass malware detection.
How do I fix CVE-2008-5524?
To fix CVE-2008-5524, users should upgrade to the latest version of CAT-QuickHeal that includes patches for this vulnerability.
Which versions of CAT-QuickHeal are affected by CVE-2008-5524?
CVE-2008-5524 affects CAT-QuickHeal versions 9.50 and 10.00.
Can CVE-2008-5524 be exploited through Internet Explorer?
Yes, CVE-2008-5524 can be exploited when using Internet Explorer 6 or 7.
What kind of attacks can CVE-2008-5524 facilitate?
CVE-2008-5524 can facilitate attacks that bypass malware detection in HTML documents by manipulating file headers.