AOH :: HP Unsorted C :: VA3422.HTM

Changes : Trendmicro multiple bypass/evasions
Changes : Trendmicro multiple bypass/evasions
Changes : Trendmicro multiple bypass/evasions


           UPDATE : Trendmicro RAR / CAB bypass evasion

CHANGES to original advisory [TZO-172009] Trendmicro : 

Status     : RAR / CAB  issue WILL be patched on June 17

Quoting vendor : 
"This vulnerability is capable of allowing attackers to send RAR files 
with corrupted RAR headers through our gateway products, which bypass 
the compressed files without scanning them."

This   just  goes  to  proove  that  publishing changes perception, as
customers   read,   react   and  complain.  (Trend  previously  denied
patching). In other words, always publish even if the vendor denies

In  the  name  of all TrendMicro customers I would like to thank those
customers that reacted and complained. Wihtout publication there is no
change, without those reacting to advisories there is neither.

Prooves #2 and #5 at 
to be valid.

Thierry Zoller

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2015 AOH
We do not send spam. If you have received spam bearing an email address, please forward it with full headers to