Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xpvv-w5mx-7x26

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antivirus, Cyber Security Pro (macOS), Cyber Security (macOS), Mobile Security for Android, Smart TV Security, and NOD32 Antivirus 4 for Linux Desktop.

The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antivirus, Cyber Security Pro (macOS), Cyber Security (macOS), Mobile Security for Android, Smart TV Security, and NOD32 Antivirus 4 for Linux Desktop.

EPSS

Процентиль: 64%
0.00469
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.8
nvd
почти 6 лет назад

The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antivirus, Cyber Security Pro (macOS), Cyber Security (macOS), Mobile Security for Android, Smart TV Security, and NOD32 Antivirus 4 for Linux Desktop.

EPSS

Процентиль: 64%
0.00469
Низкий

Дефекты

CWE-20