Remote Code Execution Risk in eTrust CA by Computer Associates
CVE-2005-3372

Currently unrated

Key Information:

Vendor

Broadcom

Vendor
CVE Published:
30 October 2005

What is CVE-2005-3372?

The vulnerability exists within eTrust CA 7.0.1.4 that utilizes the 11.9.1 engine, allowing remote attackers to evade virus scanning mechanisms. This occurs when specific file types, such as BAT, HTML, and EML, are manipulated to include an 'MZ' magic byte sequence commonly associated with executable files. As a result, these files can be misclassified as safe, leading to potential execution of malicious content on the user’s system. The issue is exemplified by a 'triple-headed' file containing EXE, EML, and HTML content, adeptly exploiting this misinterpretation and highlighting a significant risk for users relying on this security solution.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2005-3372 : Remote Code Execution Risk in eTrust CA by Computer Associates