Forums: Multi-vendor Bzip2 Antivirus Software Dos - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Multi-vendor Bzip2 Antivirus Software Dos

#1 User is offline   MindSmith 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 94
  • Joined: 16-August 03

Post icon  Posted 12 January 2004 - 10:48 PM

:P

Bugtraq id 9393
Object
Class Failure to Handle Exceptional Conditions
Cve CVE-MAP-NOMATCH

Remotely Exploitable Yes
Locally Exloitable No
Published Jan 09, 2004
Updated Jan 10, 2004


Details:
Multiple vendor antivirus software applications have been reported to be prone to a denial of service vulnerability. This issue presents itself when an affected application attempts to decompress an excessively large bzip2 archive.

Kaspersky AntiVirus for Linux 5.0.1.0, Trend Micro InterScan VirusWall 3.8 Build 1130, and McAfee Virus Scan for Linux v4.16.0 have been reported to be prone to this issue, however, it is likely that other products are affected as well.

Exploit:

No exploit is required.

Example bzip2 archives may be downloaded from the following:

ftp://ftp.aerasec.de...ries/bzip2bomb/

Source: http://www.securityf.../bid/9393/info/
MindSmith
#include <std.disclaimer.H>
0

#2 User is offline   matiano 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 59
  • Joined: 21-September 03

Posted 13 January 2004 - 07:55 AM

Dr. Peter Bieringer, Autor of the investigation of AERAsec, points
out that it is possible to later falsify the header information in ZIP
files. In addition a normal HEX editor is sufficient. If a scanner
examines only the headers and not additionally the current size, it is
dmit susceptible to ZIP bombs likewise.also its possible with win avs too :rolleyes:
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting