CVE-2020-9264

ESET Archive Support Module before 1296 allows virus-detection bypass via a crafted Compression Information Field in a ZIP archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antivirus, Cyber Security Pro (macOS), Cyber Security (macOS), Mobile Security for Android, Smart TV Security, and NOD32 Antivirus 4 for Linux Desktop.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:eset:cyber_security:*:*:*:*:*:macos:*:*
cpe:2.3:a:eset:cyber_security:*:*:*:*:pro:macos:*:*
cpe:2.3:a:eset:internet_security:*:*:*:*:*:*:*:*
cpe:2.3:a:eset:mobile_security:*:*:*:*:*:android:*:*
cpe:2.3:a:eset:nod32_antivirus:*:*:*:*:*:*:*:*
cpe:2.3:a:eset:nod32_antivirus:4:*:*:*:*:linux:*:*
cpe:2.3:a:eset:smart_security:*:*:*:*:premium:*:*:*
cpe:2.3:a:eset:smart_tv_security:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:40

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2020/Feb/21 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2020/Feb/21 - Mailing List, Third Party Advisory
References () https://blog.zoller.lu/p/tzo-11-2020-eset-generic-malformed.html - Third Party Advisory () https://blog.zoller.lu/p/tzo-11-2020-eset-generic-malformed.html - Third Party Advisory
References () https://support.eset.com/en/ca7387-modules-review-december-2019 - Release Notes () https://support.eset.com/en/ca7387-modules-review-december-2019 - Release Notes

Information

Published : 2020-02-18 15:15

Updated : 2024-11-21 05:40


NVD link : CVE-2020-9264

Mitre link : CVE-2020-9264

CVE.ORG link : CVE-2020-9264


JSON object : View

Products Affected

eset

  • cyber_security
  • internet_security
  • mobile_security
  • smart_security
  • smart_tv_security
  • nod32_antivirus
CWE
CWE-436

Interpretation Conflict