exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

F-SECURE Generic Malformed Container Bypass

F-SECURE Generic Malformed Container Bypass
Posted Feb 25, 2020
Authored by Thierry Zoller

The F-SECURE parsing engine supports the GZIP Archive. The parsing engine can be bypassed by manipulating a GZIP archive (Compression Method). This way the User can extract the file but the AV Engine cannot giving the file a clean pass. Various products and versions are affected.

tags | advisory
advisories | CVE-2020-9342
SHA-256 | fbec8e3dcdca05c0034af0f09e6fb074d27522a6d8e9187b70e6a9d79f55cbb6

F-SECURE Generic Malformed Container Bypass

Change Mirror Download
________________________________________________________________________

From the low-hanging-fruit-department
F-SECURE Generic Malformed Container bypass (GZIP)
________________________________________________________________________

Ref : [TZO-16-2020] - F-SECURE Generic Malformed Container
bypass (GZIP)
Vendor : F-SECURE
Status : Patched
CVE : CVE-2020-9342
Blog :
https://blog.zoller.lu/p/tzo-16-2020-f-secure-generic-malformed.html
Vulnerability Dislosure Policy: https://caravelahq.com/b/policy/20949

Affected Products
=================
F-Secure Email and Server Security
F-Secure Internet GateKeeper
F-SECURE CLOUD PROTECTION FOR SALESFORCE

Linux below 17.0.605.474

I. Background
----------------------------
Quote: "Unprecedented challenges threaten to undermine the very survival
of society. Only unprecedented innovation can prevent irreversible
disasters. This is only possible if we
trust the technology that can bring us together.

From our humble beginnings more than thirty years ago, F-Secure has
grown into a reliable cyber security leader, earning the trust of
organizations and people around the world."

II. Description
----------------------------
The parsing engine supports the GZIP Archive. The parsing engine can be
bypassed by manipulating a GZIP archive (Compression Method). This way
the User can extract the file but the AV Engine cannot giving the file a
clean pass.


III. Impact
----------------------------
Impacts depends on the contextual use of the product and engine within
the organisation of a customer. Gateway Products (Email, HTTP Proxy etc)
may allow the file through unscanned and give it a clean bill of health.
Server side AV software will not be able to discover
any code or sample contained within this ISO file and it will not raise
suspicion even if you know exactly what you are looking for (Which is
for example great to hide your implants
or Exfiltration/Pivot Server).

There is a lot more to be said about this bug class, so rather than bore
you with it in this advisory I provide a link to my 2009 blog post
http://blog.zoller.lu/2009/04/case-for-av-bypassesevasions.html

IV. Patch / Advisory
----------------------------
- For the unix version (IGK) the fix was released on 20th January with
library version 17.0.605.474
- For Windows the version was already out in December 2019. There were
also avira's fixes as well.

"We can conclude that January 20th date, since that is when the final
fixes went out to production."

V. Disclosure timeline
----------------------------

We would like to thank F-Secure for their customer oriented way of
handling this vulnerability.

- NOV 14 2019
Initiated Vulnerability coordination

- FEB 05 2020
F-Secure notifies me that they have patched the flaw.
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close