A vulnerability has been reported in Trend Micro products, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to a divide-by-zero error within the anti-virus engine when processing UPX compressed executables. This can be exploited to e.g. crash the system (Windows-based system) or application (library-based engine) when scanning a specially crafted UPX compressed executable file.
The vulnerability reportedly affects all Trend Micro products that use Scan Engine version 8.0 and above with Pattern File technology.
Solution Update the virus pattern file to OPR 4.335.00 or higher.
Provided and/or discovered by Discovered by an anonymous person and reported via iDefense Labs.
Do you have additional information related to this advisory?
Please provide information about patches, mitigating factors, new
versions, exploits, faulty patches, links, and other relevant data by
posting comments to this Advisory. You can also send this information to
vuln@secunia.com
Subject: Trend Micro Products UPX Processing Denial of Service
No posts yet
You must be logged in to post a comment.
Secunia Customer Login
Not a customer already?
Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance.