Jump to content

Researchers Find Hole in Trend Micro AntiVirus Lib


scuzzman
 Share

Recommended Posts

Thirty products, including e-mail services such as Hotmail, affected by flaw.

John Dunn, Techworld.com

Friday, February 25, 2005

A critical flaw has been discovered in Trend Micro's AntiVirus Library, which is used by all the company's desktop, server, and gateway security products.

The library is also used by ISPs and e-mail services such as Hotmail, and in third-party security products that use licensed versions of the antivirus software, greatly widening the scope of the new alert. The full list of Trend Micro products affected by the flaw runs to a total of 30 products.

According to the company advisory, the problem lies with the way the library handles files compressed using the ARJ standard. "Thus, it is possible to create a specially crafted ARJ archive file that overwrites data after the allocated 512-byte buffer. This specially crafted file could possibly execute an arbitrary code," continues the warning, a technically accurate but opaque way of saying that a virus code could in certain circumstances be hidden inside an archive file and not be detected.

Original story here.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy