Description: A vulnerability has been reported in eTrust Antivirus, which can be exploited by malware to bypass certain scanning functionality.
The vulnerability is caused due to an error in the decompression engine (Arclib.dll) when parsing .zip archive headers and can be exploited via a specially crafted .zip archive where the uncompressed size of the archived file has been modified within the local and global headers.
Successful exploitation causes malware in a specially crafted .zip archive to pass the scanning functionality undetected.
NOTE: This is not a critical issue on client systems, as the malware still is detected upon execution by the eTrust Antivirus Real-Time scanner.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.