Description
Heap-based buffer overflow in Trend Micro AntiVirus Library VSAPI before 7.510, as used in multiple Trend Micro products, allows remote attackers to execute arbitrary code via a crafted ARJ file with long header file names that modify pointers within a structure.
Affected products
- Trend Micro / client-server-messaging_suite_smbgold – gold
- Trend Micro / client-server_suite_smbgold – gold
- Trend Micro / control_managergold – gold
- Trend Micro / control_managergold – gold
- Trend Micro / control_managernetware – netware
- Trend Micro / control_managergold – gold
- Trend Micro / control_managergold – gold
- Trend Micro / control_managergold – gold
- Trend Micro / interscan_emanager3.6 – 3.6
- Trend Micro / interscan_emanager3.5 – 3.5
- Trend Micro / interscan_emanager3.5.2 – 3.5.2
- Trend Micro / interscan_emanager3.6 – 3.6
- Trend Micro / interscan_emanager3.51 – 3.51
- Trend Micro / interscan_emanager3.51_j – 3.51_j
- Trend Micro / interscan_messaging_security_suite3.81 – 3.81
- Trend Micro / interscan_messaging_security_suite5.5 – 5.5
- Trend Micro / interscan_messaging_security_suitegold – gold
- Trend Micro / interscan_messaging_security_suitegold – gold
- Trend Micro / interscan_messaging_security_suitegold – gold
- Trend Micro / interscan_viruswall3.52_build1466 – 3.52_build1466
- Trend Micro / interscan_viruswall3.0.1 – 3.0.1
- Trend Micro / interscan_viruswall3.0.1 – 3.0.1
- Trend Micro / interscan_viruswall3.4 – 3.4
- Trend Micro / interscan_viruswall3.5 – 3.5
- Trend Micro / interscan_viruswall3.6 – 3.6
- Trend Micro / interscan_viruswall3.6 – 3.6
- Trend Micro / interscan_viruswall3.6 – 3.6
- Trend Micro / interscan_viruswall3.6 – 3.6
- Trend Micro / interscan_viruswall3.6.5 – 3.6.5
- Trend Micro / interscan_viruswall3.51 – 3.51
- Trend Micro / interscan_viruswall3.52 – 3.52
- Trend Micro / interscan_viruswall5.1 – 5.1
- Trend Micro / interscan_viruswallgold – gold
- Trend Micro / interscan_viruswallgold – gold
- Trend Micro / interscan_viruswallgold – gold
- Trend Micro / interscan_viruswallgold – gold
- Trend Micro / interscan_viruswallgold – gold
- Trend Micro / interscan_webmanager2.0 – 2.0
- Trend Micro / interscan_webmanager2.1 – 2.1
- Trend Micro / interscan_webmanager1.2 – 1.2
- Trend Micro / interscan_webprotectgold – gold
- Trend Micro / interscan_web_security_suitegold – gold
- Trend Micro / interscan_web_security_suitegold – gold
- Trend Micro / interscan_web_security_suitegold – gold
- Trend Micro / officescan3.0 – 3.0
- Trend Micro / officescancorporate_3.0 – corporate_3.0
- Trend Micro / officescancorporate_3.1.1 – corporate_3.1.1
- Trend Micro / officescancorporate_3.5 – corporate_3.5
- Trend Micro / officescancorporate_3.5 – corporate_3.5
- Trend Micro / officescancorporate_3.11 – corporate_3.11
- Trend Micro / officescancorporate_3.11 – corporate_3.11
- Trend Micro / officescancorporate_3.13 – corporate_3.13
- Trend Micro / officescancorporate_3.13 – corporate_3.13
- Trend Micro / officescancorporate_3.54 – corporate_3.54
- Trend Micro / officescancorporate_5.02 – corporate_5.02
- Trend Micro / officescancorporate_5.5 – corporate_5.5
- Trend Micro / officescancorporate_5.58 – corporate_5.58
- Trend Micro / officescancorporate_6.5 – corporate_6.5
- Trend Micro / pc-cillin6.0 – 6.0
- Trend Micro / pc-cillin2000 – 2000
- Trend Micro / pc-cillin2002 – 2002
- Trend Micro / pc-cillin2003 – 2003
- Trend Micro / portalprotect1.0 – 1.0
- Trend Micro / scanmail2.6 – 2.6
- Trend Micro / scanmail2.51 – 2.51
- Trend Micro / scanmail3.8 – 3.8
- Trend Micro / scanmail3.81 – 3.81
- Trend Micro / scanmail6.1 – 6.1
- Trend Micro / scanmailgold – gold
- Trend Micro / scanmailgold – gold
- Trend Micro / scanmailgold – gold
- Trend Micro / scanmailgold – gold
- Trend Micro / scanmailgold – gold
- Trend Micro / scanmail_emanager
- Trend Micro / serverprotect1.3 – 1.3
- Trend Micro / serverprotect1.25_2007-02-16 – 1.25_2007-02-16
- Trend Micro / serverprotect2.5 – 2.5
- Trend Micro / serverprotect5.3.1 – 5.3.1
References
- VENDOR_ADVISORYhttp://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+VSAPI+ARJ+parsing+could+allow+Remote+Code+execution
- MISChttp://securitytracker.com/id?1013290
- MISChttp://securitytracker.com/id?1013289
- MISChttp://xforce.iss.net/xforce/alerts/id/189
- VENDOR_ADVISORYhttp://secunia.com/advisories/14396
- MISChttp://www.securityfocus.com/bid/12643