The parsing engine in ClamAV versions below 0.96 can be bypassed by manipulating CAB (Filesize) archives in a “certain way” that the ClamAV engine cannot extract the content but the end user is able to.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/78528/TZO-43-2009.txt
Source: https://packetstormsecurity.com/files/78528/ClamAV-0.95-CAB-Evasion.html

