We received a notification concerning a possible vulnerability of bypassing AV products. A blog post discusses a generic bypass of RAR files in Aladdin products could be found here:
http://blog.zoller.lu/2009/04/aladdin-esafe-generic-evasion-bypass.html
The Possible Vulnerability
It has been claimed that, due to a generic bug in archive extracting mechanisms of multiple AV products, a specially crafted archive file containing a malicious file may bypass eSafe as clean.
We have acted on the issue after two days since its first coming into view. eSafe security team together with eSafe security architect have fully investigated this possible vulnerability and have concluded that it is in fact negligible. The impact of this vulnerability is non reproducible on all major applications and the specially crafted RAR archive could not be opened – thus the risk “hidden” within it is not an actual threat.
A specially crafted archive file cannot be extracted by common archive extractors (WinRAR, WinZip, etc), because of the fact that it requires special tools in order to be extracted properly. This means that in case a customer receives such a specially crafted archive file, he will not be able to extract it.
Impact and Fix
The eSafe products affected by this vulnerability are 7.1, 7.0, and 6. The security impact of this vulnerability is low-negligible. For the protection of our customers at any event, yesterday, and within three business days, eSafe released a hot fix addressing this issue, among other issues.