CVE-2005-3374 describes a multiple interpretation error in F-Prot Antivirus 3.16c, allowing attackers to bypass virus scanning. This vulnerability occurs when a malicious file, such as a BAT, HTML, or EML file, is disguised with an "MZ" magic byte sequence, typically associated with executables. F-Prot incorrectly identifies these files as safe, even though they can still be executed as dangerous file types by other applications, potentially leading to compromise. The CVSS score of 5.1 indicates a medium severity, with a network attack vector and high attack complexity, potentially impacting confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.16cCPE matchmatch criteria | cpe:2.3:a:frisk_software:f-prot_antivirus:3.16c:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.