TrendMicro Anti-Virus vulnerability

Published: 2007-02-08
Last Updated: 2007-02-08 10:03:52 UTC
by Daniel Wesemann (Version: 1)
A buffer overflow vulnerability in the UPX parser of TrendMicro Antivirus seems to affect the product pretty much in all its incarnations. See   According to this, applying the latest pattern is sufficient to plug the problem until a new version of the engine (8.5) gets released.  Chances are though that the trend (no pun intended) will continue that AV products themselves contain the same type of  vulnerabilities they claim to shield other software against. Quis custodiet ipsos custodes ?
