Description
Multiple unspecified vulnerabilities in the Arclib library (arclib.dll) before 7.3.0.15 in the CA Anti-Virus engine for CA Anti-Virus for the Enterprise 7.1, r8, and r8.1; Anti-Virus 2007 v8 and 2008; Internet Security Suite 2007 v3 and 2008; and other CA products allow remote attackers to bypass virus detection via a malformed archive file.
Affected products
- Broadcom / anti-spyware2007 – 2007
- Broadcom / anti-spyware2008 – 2008
- Broadcom / anti-spyware_for_the_enterprise8.1 – 8.1
- Broadcom / anti-spyware_for_the_enterpriser8 – r8
- Broadcom / anti-virus2008 – 2008
- Broadcom / anti-virus2007 – 2007
- Broadcom / anti-virus_for_the_enterprise7.1 – 7.1
- Broadcom / anti-virus_for_the_enterprise8.1 – 8.1
- Broadcom / anti-virus_for_the_enterpriser8 – r8
- Broadcom / antivirus_gateway7.1 – 7.1
- Broadcom / anti-virus_sdk
- Broadcom / arcserve_client_agent
- Broadcom / common_services11 – 11
- Broadcom / common_services11.1 – 11.1
- Broadcom / etrust_ez_antivirusr6.1 – r6.1
- Broadcom / etrust_ez_antivirusr7 – r7
- Broadcom / etrust_intrusion_detection3.0 – 3.0
- Broadcom / etrust_intrusion_detection4.0 – 4.0
- Broadcom / network_and_systems_managementr3.1 – r3.1
- Broadcom / network_and_systems_managementr3.0 – r3.0
- Broadcom / network_and_systems_managementr11 – r11
- Broadcom / network_and_systems_managementr11.1 – r11.1
- Broadcom / secure_content_manager8.0 – 8.0
- Broadcom / secure_content_manager8.1 – 8.1
- ca / arcserve_backupr11.1 – r11.1
- ca / arcserve_backupr11.1 – r11.1
- ca / arcserve_backupr11.5_nil_ – r11.5_nil_
- ca / arcserve_backupr11.5_nil_ – r11.5_nil_
- ca / arcserve_backupr12.0_nil_ – r12.0_nil_
- ca / etrust_intrusion_detection2.0 – 2.0
- ca / etrust_intrusion_detection3.0 – 3.0
- ca / internet_security_suite_20073 – 3
- ca / internet_security_suite_2008
- ca / internet_security_suite_plus_2008
- ca / protection_suitesr2 – r2
- ca / protection_suitesr3 – r3
- ca / protection_suitesr3.1 – r3.1
- ca / threat_manager_for_the_enterprise8.1 – 8.1
- ca / threat_manager_for_the_enterpriser8 – r8
References
- MISChttp://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197601
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2009/0270
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/48261
- MISChttp://www.securityfocus.com/bid/33464
- MISChttp://www.securityfocus.com/archive/1/500417/100/0/threaded
- MISChttp://www.securitytracker.com/id?1021639
- MISChttp://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/26/ca20090126-01-ca-anti-virus-engine-detection-evasion-multiple-vulnerabilities.aspx