BitDefender engine vulnerability: advisory disclosure and fixOn 4th of July, we were contacted by Alexander Hagenah to inform us that he discovered a possible vulnerability in our
software.
The reported vulnerability could be exploited by a malicious attacker to
send malformed infected messages, bypassing the av protection.
Filename Format String VulnerabilityThe vulnerability is caused due to a format string error when generating the scan report file. This can potentially be exploited to execute arbitrary code when a file or directory containing format string specifiers in its name (e.g. %.8X%.8X) is scanned.
Showing articles from
1 to
3 of
3Page 1