CVE-2009-1348: Input Validation
The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Email Servers, Email Gateway, and Active Virus Defense allows remote attackers to bypass virus detection via (1) an invalid Headflags field in a malformed RAR archive, (2) an invalid Packsize field in a malformed RAR archive, or (3) an invalid Filelength field in a malformed ZIP archive.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1348?
CVE-2009-1348 is considered a medium severity vulnerability due to potential bypass of virus detection.
How do I fix CVE-2009-1348?
To fix CVE-2009-1348, ensure that you update your McAfee software to the latest version and apply any available patches.
Which McAfee products are affected by CVE-2009-1348?
CVE-2009-1348 affects several McAfee products including VirusScan, Total Protection, and Internet Security.
Can CVE-2009-1348 be exploited remotely?
Yes, CVE-2009-1348 allows remote attackers to bypass virus detection capabilities.
What should I do if I am using vulnerable McAfee software related to CVE-2009-1348?
If using vulnerable McAfee software, it's important to upgrade to the latest version immediately to mitigate the risk.