Multiple Vendor Anti-Virus Scanner Remote Denial Of Service Vulnerability
BID:10537
Info
Multiple Vendor Anti-Virus Scanner Remote Denial Of Service Vulnerability
| Bugtraq ID: | 10537 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2004 12:00AM |
| Updated: | Jun 14 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Bipin Gautam <[email protected]>. |
| Vulnerable: |
Symantec Norton AntiVirus Corporate Edition 7.60.build 926 Symantec Norton AntiVirus 2003 Professional Edition Symantec Norton Antivirus 2003 0 Symantec Norton AntiVirus 2002 Professional Edition Symantec Norton AntiVirus 2002 0 Symantec AntiVirus for Handhelds 3.0 RAV AntiVirus Online Virus Scan Panda Antivirus Platinum 2.0 McAfee VirusScan Enterprise 7.1 McAfee VirusScan 6.0 McAfee UVscan scan for Linux 4.3.20 Frisk Software F-Prot Antivirus for Linux and BSD 4.4.2 Dr.Web Dr.Web Computer Associates InoculateIT 6.0 Computer Associates eTrust Antivirus 6.0 Clam Anti-Virus ClamAV 0.70 AVG AVG Anti-Virus 7.0.251 AVG AVG Anti-Virus 6.0.710 |
| Not Vulnerable: |
Computer Associates eTrust Antivirus 7.0 SP2 Computer Associates eTrust Antivirus 7.0 |
Discussion
Multiple Vendor Anti-Virus Scanner Remote Denial Of Service Vulnerability
Multiple vendor anti-virus scanning software is reported prone to a remote denial of service vulnerability.
The issue is reported to present itself when certain malicious archives containing large quantities of data are scanned.
In the supplied example approximately 300 Gigabytes of data is archived in many different archive types. This archive may be transmitted to a client or submitted to an online anti-virus scanning service in order to crash the anti-virus software.
Multiple vendor anti-virus scanning software is reported prone to a remote denial of service vulnerability.
The issue is reported to present itself when certain malicious archives containing large quantities of data are scanned.
In the supplied example approximately 300 Gigabytes of data is archived in many different archive types. This archive may be transmitted to a client or submitted to an online anti-virus scanning service in order to crash the anti-virus software.
Exploit / POC
Multiple Vendor Anti-Virus Scanner Remote Denial Of Service Vulnerability
There is no exploit required. A proof of concept to exploit this vulnerability is publically available.
There is no exploit required. A proof of concept to exploit this vulnerability is publically available.
Solution / Fix
Multiple Vendor Anti-Virus Scanner Remote Denial Of Service Vulnerability
Solution:
Computer Associates has reported that this vulnerability affects build 85 of eTrust Antivirus 6.0. eTrust Antivirus 6.0 builds; 96, 101, 102 and the cumulative fix are not reported to be affected. Customers are advised to contact Computer Associates for further information.
Solution:
Computer Associates has reported that this vulnerability affects build 85 of eTrust Antivirus 6.0. eTrust Antivirus 6.0 builds; 96, 101, 102 and the cumulative fix are not reported to be affected. Customers are advised to contact Computer Associates for further information.
References
Multiple Vendor Anti-Virus Scanner Remote Denial Of Service Vulnerability
References:
References:
- Antivirus/Trojan/Spyware scanners DoS [summary] (Bipin Gautam
)