CVE-2008-5548: Input Validation
VirusBuster 4.5.11.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5548?
CVE-2008-5548 has a medium severity level due to its ability to allow malware to bypass detection.
How do I fix CVE-2008-5548?
To fix CVE-2008-5548, ensure you are using an updated version of VirusBuster that addresses this vulnerability.
What versions of VirusBuster are affected by CVE-2008-5548?
CVE-2008-5548 specifically affects VirusBuster version 4.5.11.0.
Which browsers are involved in CVE-2008-5548?
CVE-2008-5548 involves Internet Explorer versions 6 and 7.
What types of file extensions can be used to exploit CVE-2008-5548?
CVE-2008-5548 can be exploited using files with no extension, .txt, or .jpg extensions.