Likes Likes:  0
Resultaten 1 tot 5 van de 5
Geen
  1. #1
    list@rem0te.com
    ClamAV Multiple Rem0te Buffer Overflows
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    ClamAV Multiple Rem0te Buffer Overflows

    Date
    July 25, 2005

    Vulnerability
    ClamAV is the most widely used GPL antivirus library today. It provides f=
    ile format support for virus analysis. During analysis ClamAV Antivirus L=
    ibrary is vulnerable to buffer overflows allowing attackers complete cont=
    rol of the system. These vulnerabilities can be exploited remotely withou=
    t user interaction or authentication through common protocols such as SMT=
    P, SMB, HTTP, FTP, etc.

    Specifically, ClamAV is responsible for parsing multiple file formats. At=
    least 4 of its file format processors contain remote security bugs. Spec=
    ifically, during the processing of TNEF, CHM, & FSG formats an attacker i=
    s able to trigger several integer overflows that allow attackers to overw=
    rite heap data to obtain complete control of the system. These vulnerabil=
    ities can be reached by default and triggered without user interaction by=
    sending an e-mail containing crafted data.

    Impact
    Successful exploitation of ClamAV protected systems allows attackers unau=
    thorized control of data and related privileges. It also provides leverag=
    e for further network compromise. ClamAV implementations are likely vulne=
    rable in their default configuration.

    Affected Products
    ClamAV =E2=80=93 0.86.1 (current) and prior

    There are numerous implementations of ClamAV listed on their site which a=
    re likely vulnerable. One party of note is Apple. Apple includes ClamAV b=
    y default in Mac OS X Server. In addition, ClamAV has been ported to wind=
    ows and a variety of other platforms by third parties who=E2=80=99s imple=
    mentations are also likely vulnerable. Refer to vendor for specifics.

    Credit
    These vulnerabilities were discovered and researched by Neel Mehta & Alex=
    Wheeler.

    Contact
    security@rem0te.com

    Details
    http://www.rem0te.com/public/images/clamav.pdf







  2. #2
    nick
    ClamAV Multiple Rem0te Buffer Overflows
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: ClamAV Multiple Rem0te Buffer Overflows

    list@rem0te.com wrote:
    > Date
    > July 25, 2005
    >
    > Vulnerability
    > ClamAV is the most widely used GPL antivirus library today. It provides file format support for virus analysis. During analysis ClamAV Antivirus Library is vulnerable to buffer overflows allowing attackers complete control of the system. These vulnerabi

    lities can be exploited remotely without user interaction or authentication through common protocols such as SMTP, SMB, HTTP, FTP, etc.
    >
    > Specifically, ClamAV is responsible for parsing multiple file formats. At least 4 of its file format processors contain remote security bugs. Specifically, during the processing of TNEF, CHM, & FSG formats an attacker is able to trigger several integer

    overflows that allow attackers to overwrite heap data to obtain complete control of the system. These vulnerabilities can be reached by default and triggered without user interaction by sending an e-mail containing crafted data.
    >
    > Impact
    > Successful exploitation of ClamAV protected systems allows attackers unauthorized control of data and related privileges. It also provides leverage for further network compromise. ClamAV implementations are likely vulnerable in their default configurati

    on.
    >
    > Affected Products
    > ClamAV – 0.86.1 (current) and prior
    >
    > There are numerous implementations of ClamAV listed on their site which are likely vulnerable. One party of note is Apple. Apple includes ClamAV by default in Mac OS X Server. In addition, ClamAV has been ported to windows and a variety of other platfor

    ms by third parties who’s implementations are also likely vulnerable. Refer to vendor for specifics.
    >
    > Credit
    > These vulnerabilities were discovered and researched by Neel Mehta & Alex Wheeler.
    >
    > Contact
    > security@rem0te.com
    >
    > Details
    > http://www.rem0te.com/public/images/clamav.pdf
    >
    >
    >
    >
    >
    >


    The clamav.net front page says "Latest ClamAV stable release is: 0.86.2".

    Is this included in your advisory?

  3. #3
    Sec-Tec Lists
    ClamAV Multiple Rem0te Buffer Overflows
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    RE: ClamAV Multiple Rem0te Buffer Overflows

    >The clamav.net front page says "Latest ClamAV stable release is: =
    0.86.2".
    >
    >Is this included in your advisory?


    The release notes for 0.86.2 say:

    "Changes in this release include fixes for three possible integer =
    overflows in libclamav"



  4. #4
    Steven M. Christey
    ClamAV Multiple Rem0te Buffer Overflows
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: ClamAV Multiple Rem0te Buffer Overflows


    >The release notes for 0.86.2 say:
    >
    >"Changes in this release include fixes for three possible integer
    >overflows in libclamav"


    Simply assuming that a single-line changelog entry is sufficient
    acknowledgement of a published vulnerability is dangerous. Such
    assumptions are frequently wrong. (However, in this case, Alex
    Wheeler is credited in the more detailed changelog in the release
    notes).

    However...

    The original advisory said:

    "At least 4 of its file format processors contain remote security
    bugs."

    But then the advisory only lists 3 formats.

    So, was this just a typo by the researchers? Or are there really 4
    bugs, and the latest release still has one bug that hasn't been fixed
    yet?

    This demonstrates one of the Four I's of security advisory problems,
    namely Inconsistency. The other three are Inaccurate, Incomplete, or
    Incomprehensible.

    - Steve

  5. #5
    list@rem0te.com
    ClamAV Multiple Rem0te Buffer Overflows
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: ClamAV Multiple Rem0te Buffer Overflows

    >But then the advisory only lists 3 formats.

    >So, was this just a typo by the researchers? Or are there really 4
    >bugs, and the latest release still has one bug that hasn't been fixed
    >yet?


    >This demonstrates one of the Four I's of security advisory problems,
    >namely Inconsistency. The other three are Inaccurate, Incomplete, or
    >Incomprehensible.


    The advisory on rem0te.com is correct. On the same note, the release note=
    s by clamav are not completely wrong. They fixed the same mistake in two =
    different processors for the same format. So clamav is probably counting =
    the two instances of the same mistake as one mistake.

    Specifically, one of the formats (TNEF) contained two processors with the=
    same mistake: tnef_message() & tnef_attachment(). Both were fixed by the=
    clamav team in 0.86.2.








Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics