This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Ahnlab First view 2007-11-20
Product v3 Internet Security Last view 2018-04-24
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:ahnlab:v3_internet_security:2011.01.18.00:*:*:*:*:*:*:* 8
cpe:2.3:a:ahnlab:v3_internet_security:2008.9.13.0:*:*:*:*:*:*:* 1
cpe:2.3:a:ahnlab:v3_internet_security:2008.12.4.1:*:*:*:*:*:*:* 1
cpe:2.3:a:ahnlab:v3_internet_security:2008:*:platinum:*:*:*:*:* 1
cpe:2.3:a:ahnlab:v3_internet_security:8.0.7.5:*:*:*:*:*:*:* 1

Related : CVE

  Date Alert Description
7.8 2018-04-24 CVE-2013-3947

Buffer overflow in MedCoreD.sys in AhnLab V3 Internet Security 8.0.7.5 (Build 1373) allows local users to gain privileges via a crafted 0xA3350014 IOCTL call.

4.3 2012-03-21 CVE-2012-1463

The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified endianness field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

4.3 2012-03-21 CVE-2012-1462

The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, Norman Antivirus 6.06.12, Sophos Anti-Virus 4.61.0, and AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11 allows remote attackers to bypass malware detection via a ZIP file containing an invalid block of data at the beginning. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ZIP parser implementations.

4.3 2012-03-21 CVE-2012-1459

The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

4.3 2012-03-21 CVE-2012-1443

The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.

4.3 2012-03-21 CVE-2012-1436

The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \2D\6C\68 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

4.3 2012-03-21 CVE-2012-1435

The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \50\4B\4C\49\54\45 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

4.3 2012-03-21 CVE-2012-1434

The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

4.3 2012-03-21 CVE-2012-1433

The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

9.3 2008-12-12 CVE-2008-5520

AhnLab V3 2008.12.4.1 and possibly 2008.9.13.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.

9.3 2007-11-20 CVE-2007-6060

AhnLab Antivirus 3 Internet Security 2008 Platinum appends data to a filename string at a location indicated by the "Filename length" field in a ZIP header, which allows remote attackers to cause a denial of service (machine crash) and possibly execute arbitrary code via a ZIP file in which this field's value is larger than the actual number of bytes in the filename.

CWE : Common Weakness Enumeration

%idName
75% (9) CWE-264 Permissions, Privileges, and Access Controls
16% (2) CWE-20 Improper Input Validation
8% (1) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer

Open Source Vulnerability Database (OSVDB)

id Description
50728 AhnLab V3 HTML Document MZ Header Multiple Filename Modification Malware Dete...
42352 AhnLab Products V3 Engine ZIP Archive Header Processing Memory Corruption

OpenVAS Exploits

id Description
2012-12-13 Name : SuSE Update for ClamAV openSUSE-SU-2012:0833-1 (ClamAV)
File : nvt/gb_suse_2012_0833_1.nasl
2012-08-30 Name : Fedora Update for clamav FEDORA-2012-9563
File : nvt/gb_fedora_2012_9563_clamav_fc17.nasl
2012-08-17 Name : Ubuntu Update for clamav USN-1482-3
File : nvt/gb_ubuntu_USN_1482_3.nasl
2012-08-10 Name : FreeBSD Ports: clamav
File : nvt/freebsd_clamav17.nasl
2012-07-16 Name : Fedora Update for clamav FEDORA-2012-9577
File : nvt/gb_fedora_2012_9577_clamav_fc16.nasl
2012-06-22 Name : Ubuntu Update for clamav USN-1482-1
File : nvt/gb_ubuntu_USN_1482_1.nasl
2012-06-22 Name : Ubuntu Update for clamav USN-1482-2
File : nvt/gb_ubuntu_USN_1482_2.nasl

Snort® IPS/IDS

Date Description
2017-10-10 ZIP file malformed header antivirus evasion attempt
RuleID : 44325 - Type : FILE-OTHER - Revision : 2
2017-10-10 RAR file malformed header antivirus evasion attempt
RuleID : 44323 - Type : FILE-OTHER - Revision : 2
2014-01-10 Portable Executable multiple antivirus evasion attempt
RuleID : 23312 - Type : FILE-EXECUTABLE - Revision : 6
2014-01-10 Portable Executable multiple antivirus evasion attempt
RuleID : 23311 - Type : FILE-EXECUTABLE - Revision : 6
2014-01-10 Portable Executable multiple antivirus evasion attempt
RuleID : 23310 - Type : FILE-EXECUTABLE - Revision : 6
2014-01-10 Portable Executable multiple antivirus evasion attempt
RuleID : 23309 - Type : FILE-EXECUTABLE - Revision : 6

Nessus® Vulnerability Scanner

id Description
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2012-362.nasl - Type: ACT_GATHER_INFO
2013-01-25 Name: The remote SuSE 11 host is missing a security update.
File: suse_11_clamav-120622.nasl - Type: ACT_GATHER_INFO
2012-08-17 Name: The remote Ubuntu host is missing one or more security-related patches.
File: ubuntu_USN-1482-3.nasl - Type: ACT_GATHER_INFO
2012-07-11 Name: The remote Fedora host is missing a security update.
File: fedora_2012-9577.nasl - Type: ACT_GATHER_INFO
2012-07-11 Name: The remote SuSE 10 host is missing a security-related patch.
File: suse_clamav-8200.nasl - Type: ACT_GATHER_INFO
2012-06-27 Name: The remote antivirus service is affected by multiple vulnerabilities.
File: clamav_0_97_5.nasl - Type: ACT_GATHER_INFO
2012-06-25 Name: The remote Fedora host is missing a security update.
File: fedora_2012-9563.nasl - Type: ACT_GATHER_INFO
2012-06-20 Name: The remote Ubuntu host is missing one or more security-related patches.
File: ubuntu_USN-1482-1.nasl - Type: ACT_GATHER_INFO
2012-06-20 Name: The remote Ubuntu host is missing one or more security-related patches.
File: ubuntu_USN-1482-2.nasl - Type: ACT_GATHER_INFO
2012-06-18 Name: The remote FreeBSD host is missing one or more security-related updates.
File: freebsd_pkg_eb12ebeeb7af11e1b5e0000c299b62e1.nasl - Type: ACT_GATHER_INFO