|
Brought to you by:
Suppliers of:
|
|
|
| |
| The parsing engine can be bypassed by manipulating RAR,ZIP archives in a "certain way" that the Clamav engine cannot extract the content but the end user is able to. |
| |
Credit:
The information has been provided by Thierry Zoller.
The original article can be found at: http://blog.zoller.lu/2009/05/advisory-clamav-generic-bypass.html
|
| |
Vulnerable Systems:
* ClamAV prior to version 0.95.2
Immune Systems:
* ClamAV version 0.95.2 and later
In essence a bypass is simple to understand - the AV scanning engine, that is the logic and code paths that detect if code is malicious or not, are evaded. This is not to be confused with the manipulation of existing malware in order to be no longer detected - these could be consider an "evasion" but only for that single sample - Thierry does not consider these to be a security problem per se.
Evasions presented here are generic, meaning that they represent a generic method to evade detection .
To know more about the impact and type of "evasion", please see: "A case for AV bypasses/evasions" http://blog.zoller.lu/2009/04/case-for-av-bypassesevasions.html
|
|
|
|
|