J-Security Center

Title: Multiple Trend Micro Antivirus RAR Archive Remote Denial Of Service Vulnerability

Severity: MODERATE

Description:

Trend Micro provides antivirus and security applications available for multiple operating systems.

Multiple Trend Micro antivirus applications are prone to a remote denial-of-service vulnerability because the software fails to properly handle certain file types, resulting in the excessive consumption of system resources.

Specifically, a denial-of-service condition affects the applications when processing malformed RAR files. An attacker may craft a malicious RAR file containing the 'head_size' and 'pack_size' fields set to zero in the 'Archive Header' section to trigger this issue. When processing this file, the application will enter an infinite loop, consuming excessive CPU resources.

An attacker may exploit this issue to crash affected computers, denying further service to users.

Trend Micro PC Cillin Internet Security 2006, Trend Micro Office Scan 7.3, and Trend Micro Server Protect 5.58 are vulnerable. Other versions may also be affected.

Affected Products:

  • Trend Micro Office Scan 7.3
  • Trend Micro PC Cillin - Internet Security 2006
  • Trend Micro Server Protect 5.58

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.