Description
The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified endianness field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.
Affected products
- ahnlab / v3_internet_security2011.01.18.00 β 2011.01.18.00
- aladdin / esafe7.0.17.0 β 7.0.17.0
- authentium / command_antivirus5.2.11.5 β 5.2.11.5
- Bitdefender / bitdefender7.2 β 7.2
- cat / quick_heal11.00 β 11.00
- Comodo / Comodo Antivirus7424 β 7424
- f-prot / f-prot_antivirus4.6.2.117 β 4.6.2.117
- F-Secure / f-secure_anti-virus9.0.16160.0 β 9.0.16160.0
- McAfee / scan_engine5.400.0.1158 β 5.400.0.1158
- norman / norman_antivirus_&_antispyware6.06.12 β 6.06.12
- nprotect / nprotect_antivirus2011-01-17.01 β 2011-01-17.01
- pandasecurity / panda_antivirus10.0.2.7 β 10.0.2.7