VBSA-2007-001: RAR module detection bypass in VirusBuster scan engine
Affected component(s): VirusBuster scan engine versions prior to 4.3.26
Vulnerability type: Detection bypass
Risk: Low
Description:
VirusBuster scan engine is unable to scan inside some corrupted RAR files.
Impact:
This problem has no impact on users as VirusBuster’s scan engine is scanning RAR files as normal binary files as well, and in case of any malware outbreak VirusBuster is able to release definitions to identify corrupted RAR files, which contain malware code.
Solution:
The vulnerability was reported on the 20th, May, 2007 and an updated scan engine was released on the 8th, June, 2007, but no futher user actions are needed due to the reasons described in the "Impact" section.
Credit:
VirusBuster would like to thank Thierry Zoller of nruns.com for reporting this issue.