CVE-2008-5526: Input Validation
DrWeb Anti-virus 4.44.0.09170, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5526?
CVE-2008-5526 is classified as a medium severity vulnerability.
How do I fix CVE-2008-5526?
To fix CVE-2008-5526, update to a newer version of Dr.Web Anti-virus that does not have this vulnerability.
What software is affected by CVE-2008-5526?
CVE-2008-5526 affects Dr.Web Anti-virus version 4.44.0.09170 when used with Internet Explorer 6 or 7.
Is CVE-2008-5526 exploitable remotely?
Yes, CVE-2008-5526 is exploitable remotely by attackers using specially crafted HTML documents.
What type of attack does CVE-2008-5526 enable?
CVE-2008-5526 enables attackers to bypass malware detection in Dr.Web Anti-virus by modifying file headers and extensions.