The F-Secure AV parsing engine before 2020-02-05 allows virus-detection bypass via crafted Compression Method data in a GZIP archive. This affects versions before 17.0.605.474 (on Linux) of Cloud Protection For Salesforce, Email and Server Security, and Internet GateKeeper.
Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.
Link | Tags |
---|---|
https://blog.zoller.lu/p/tzo-16-2020-f-secure-generic-malformed.html | third party advisory |
https://seclists.org/bugtraq/2020/Feb/33 | third party advisory mailing list |
http://packetstormsecurity.com/files/156506/F-SECURE-Generic-Malformed-Container-Bypass.html | vdb entry third party advisory |
http://seclists.org/fulldisclosure/2020/Feb/33 | third party advisory mailing list |