CVE-2009-1782
Last modified
CVE-2009-1782 is a vulnerability of currently unknown severity. Multiple F-Secure anti-virus products, including Anti-Virus for Microsoft Exchange 7.10 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, Windows 6.61 and earlier, and Linux 2.16 and earlier; Internet Security 2009 and earlier, Anti-Virus 2009 and earlier, Client Security 8.0 and earlier, and others; allow remote attackers to bypass malware detection via a crafted (1) ZIP and (2) RAR archive.. EPSS estimates a 2.21% chance of exploitation in the next 30 days.
Description
Multiple F-Secure anti-virus products, including Anti-Virus for Microsoft Exchange 7.10 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, Windows 6.61 and earlier, and Linux 2.16 and earlier; Internet Security 2009 and earlier, Anti-Virus 2009 and earlier, Client Security 8.0 and earlier, and others; allow remote attackers to bypass malware detection via a crafted (1) ZIP and (2) RAR archive.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| F-Secure | Anti-Virus | <= 4.65 |
| F-Secure | Anti-Virus | <= 5.54 |
| F-Secure | Anti-Virus | <= 5.61 |
| F-Secure | Anti-Virus | <= 6.62 |
| F-Secure | Anti-Virus | <= 7.00 |
| F-Secure | Anti-Virus | <= 7.0 |
| F-Secure | Anti-Virus | <= 7.10 |
| F-Secure | Anti-Virus | <= 8.00 |
| F-Secure | Anti-Virus | <= 8.0 |
| F-Secure | Anti-Virus | <= 2009 |
| F-Secure | Client Security | <= 8.0 |
| F-Secure | Home Server Security | <= 2009 |
| F-Secure | Internet Gatekeeper | <= 2.16 |
| F-Secure | Internet Gatekeeper | <= 3.01 |
| F-Secure | Internet Gatekeeper | <= 6.61 |
| F-Secure | Internet Security | <= 2009 |
| F-Secure | Linux Security | <= 7.01 |
| F-Secure | Linux Security | <= 7.02 |
References
- http://secunia.com/advisories/35008Vendor Advisory
- http://www.f-secure.com/en_EMEA/support/security-advisory/fsc-2009-1.htmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/1262Vendor Advisory
- http://secunia.com/advisories/35008Vendor Advisory
- http://www.f-secure.com/en_EMEA/support/security-advisory/fsc-2009-1.htmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/1262Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-1782?
How severe is CVE-2009-1782?
How do I fix CVE-2009-1782?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-1776Multiple cross-site scripting (XSS) vulnerabilities in FormM…
- CVE-2009-1777CRLF injection vulnerability in FormMail.pl in Matt Wright F…
- CVE-2009-1778SQL injection vulnerability in the new user registration fea…
- CVE-2009-1779PHP remote file inclusion vulnerability in admin.php in Frax…
- CVE-2009-1780admin.php in Frax.dk Php Recommend 1.3 and earlier does not …
- CVE-2009-1781Static code injection vulnerability in admin.php in Frax.dk …
- CVE-2009-1783Multiple FRISK Software F-Prot anti-virus products, includin…
- CVE-2009-1784The AVG parsing engine 8.5 323, as used in multiple AVG anti…
- CVE-2009-1785Cross-site scripting (XSS) vulnerability in Ulteo Open Virtu…
- CVE-2009-1786The malloc subsystem in libc in IBM AIX 5.3 and 6.1 allows l…
- CVE-2009-1787Multiple SQL injection vulnerabilities in PHP Dir Submit (ak…
- CVE-2009-1788Heap-based buffer overflow in voc_read_header in libsndfile …
Are you affected by CVE-2009-1782?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
