← Back

CVE-2005-3400

nvd nist
Published: Nov 1, 2005Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Multiple interpretation error in Fortinet 2.48.0.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug."

Affected (1)

Products: Fortinet: Fortinet
1 product
Fortinet
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.48.0.0

References (4)

Timeline

No history available yet.