CVE-2008-5532: Input Validation
Ikarus Virus Utilities T3.1.1.45.0 and possibly T3.1.1.34.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5532?
CVE-2008-5532 has a moderate severity level as it allows remote attackers to bypass malware detection.
How do I fix CVE-2008-5532?
To fix CVE-2008-5532, update Ikarus Virus Utilities to the latest version and ensure proper configuration for detection settings.
Which software is affected by CVE-2008-5532?
CVE-2008-5532 affects Ikarus Virus Utilities versions T3.1.1.34.0 and T3.1.1.45.0, when used with Internet Explorer 6 or 7.
How does CVE-2008-5532 allow malware to bypass detection?
CVE-2008-5532 allows malware to bypass detection by inserting an MZ header at the beginning of an HTML document.
Can CVE-2008-5532 affect other antivirus programs?
CVE-2008-5532 specifically affects Ikarus Virus Utilities and is not known to affect other antivirus programs.