Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2020-9342

Description

The F-Secure AV parsing engine before 2020-02-05 allows virus-detection bypass via crafted Compression Method data in a GZIP archive. This affects versions before 17.0.605.474 (on Linux) of Cloud Protection For Salesforce, Email and Server Security, and Internet GateKeeper.

POC

Reference

- http://packetstormsecurity.com/files/156506/F-SECURE-Generic-Malformed-Container-Bypass.html

- https://blog.zoller.lu/p/tzo-16-2020-f-secure-generic-malformed.html

Github

No PoCs found on GitHub currently.