Quicklinks: Home Contact


G-SEC™ regularly publishes advisories about vulnerabilities that we discovered during our research. G-SEC™ tries to follow responsible disclosure guidelines whenever possible.

More information »


F-Secure - Generic PDF detection bypass

Release mode: Coordinated
Reference : [GSEC-48-2009] - F-Secure generic PDF bypass
Vendor : http://www.f-secure.com
Status : Patched
CVE : none attributed yet
Credit : tba (probably FSC-2009-3)
Discovered by : Thierry Zoller (G-SEC)

Affected products :

Affected Plattforms

I. Background

Quote: "F-Secure offers a broad range of PC and internet security products made for your home or business, so you will always be protected. Our internet security, antivirus
and anti-spyware software is trusted by more than 180 internet service providers around the world. Moreover, with 16 global offices and a presence within more than 100 countries, F-Secure is sure to be there for you and your security software needs."

II. Description

Improper parsing of the PDF structure leads to evasion of detection of malicious PDF documents at scantime and runtime. This has been tested with several malicious PDF files and represents a generic evasion of all PDF signatures and heuristics.

General information about evasion/bypasses can be found at : http://blog.zoller.lu/2009/04/case-for-av-bypassesevasions.html

III. Impact

Known PDF exploits/malware may evade signature detection, 0day exploits may evade heuristics.

V. Disclosure timeline

Note: All trademarks mentioned herein belong to their respective owners.