CVE Database
/

CVE-2005-3401

Back to search

CVE-2005-3401

Published: Nov 1, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple interpretation error in TheHacker 5.8.4.128 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug."

VendorProductVersions

n/a

n/a

affected
n/a

References

114
third-party-advisory
x_refsource_SREASON
20051026 Update for the magic byte bug
mailing-list
x_refsource_BUGTRAQ
122
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now