CVE-2009-0042
Multiple unspecified vulnerabilities in the Arclib library (arclib.dll) before 7.3.0.15 in the CA Anti-Virus engine for CA Anti-Virus for the Enterprise 7.1, r8, and r8.1; Anti-Virus 2007 v8 and 2008; Internet Security Suite 2007 v3 and 2008; and other CA products allow remote attackers to bypass virus detection via a malformed archive file.
Published:Jan 28, 2009
Last Modified:Apr 23, 2026
EPS:Jan 28, 2009
EPSS Score:0.014
CVSS Score:10
Affected Products
Vendor
Product
Action
Vendor
Broadcom
Product
Anti-spyware
Broadcom
Anti-spyware
Vendor
Broadcom
Product
Anti-spyware For The Enterprise
Broadcom
Anti-spyware For The Enterprise
Vendor
Broadcom
Product
Anti-virus
Broadcom
Anti-virus
Vendor
Broadcom
Product
Anti-virus For The Enterprise
Broadcom
Anti-virus For The Enterprise
Vendor
Broadcom
Product
Anti-virus Sdk
Broadcom
Anti-virus Sdk
Vendor
Broadcom
Product
Antivirus Gateway
Broadcom
Antivirus Gateway
Vendor
Broadcom
Product
Arcserve Client Agent
Broadcom
Arcserve Client Agent
Vendor
Broadcom
Product
Common Services
Broadcom
Common Services
Vendor
Broadcom
Product
Etrust Ez Antivirus
Broadcom
Etrust Ez Antivirus
Vendor
Broadcom
Product
Etrust Intrusion Detection
Broadcom
Etrust Intrusion Detection
Vendor
Broadcom
Product
Network And Systems Management
Broadcom
Network And Systems Management
Vendor
Broadcom
Product
Secure Content Manager
Broadcom
Secure Content Manager
Vendor
Ca
Product
Arcserve Backup
Ca
Arcserve Backup
Vendor
Ca
Product
Etrust Intrusion Detection
Ca
Etrust Intrusion Detection
Vendor
Ca
Product
Internet Security Suite 2007
Ca
Internet Security Suite 2007
Vendor
Ca
Product
Internet Security Suite 2008
Ca
Internet Security Suite 2008
Vendor
Ca
Product
Internet Security Suite Plus 2008
Ca
Internet Security Suite Plus 2008
Vendor
Ca
Product
Protection Suites
Ca
Protection Suites
Vendor
Ca
Product
Threat Manager For The Enterprise
Ca
Threat Manager For The Enterprise
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
