Sophos Anti-Virus BZip2 Archive Handling Remote Denial Of Service Vulnerability
BID:14270
Info
Sophos Anti-Virus BZip2 Archive Handling Remote Denial Of Service Vulnerability
| Bugtraq ID: | 14270 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2005-1530 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | The individual or group that discovered this vulnerability wishes to remain anonymous. |
| Vulnerable: |
Sophos Small Business Suite 1.0 Sophos PureMessage Anti-Virus 4.6 Sophos MailMonitor for SMTP 2.1 Sophos MailMonitor for SMTP 2.0 Sophos MailMonitor for Notes/Domino Sophos Anti-Virus 5.0.1 Sophos Anti-Virus 3.95 Sophos Anti-Virus 3.91 Sophos Anti-Virus 3.90 Sophos Anti-Virus 3.86 Sophos Anti-Virus 3.85 Sophos Anti-Virus 3.84 Sophos Anti-Virus 3.83 Sophos Anti-Virus 3.82 Sophos Anti-Virus 3.81 Sophos Anti-Virus 3.80 Sophos Anti-Virus 3.79 Sophos Anti-Virus 3.78 d Sophos Anti-Virus 3.78 Sophos Anti-Virus 3.4.6 |
| Not Vulnerable: |
Sophos Anti-Virus Engine 2.30.4 Sophos Anti-Virus 5.0.4 Sophos Anti-Virus 4.5.3 Sophos Anti-Virus 3.95 |
Discussion
Sophos Anti-Virus BZip2 Archive Handling Remote Denial Of Service Vulnerability
Sophos Anti-Virus is prone to a remote denial of service vulnerability when it is configured to 'Scan inside archive files'. This is not a default setting.
The issue exists due to failure of the software to adequately sanitize 'Extra field length' values contained in BZip2 archives. Ultimately this vulnerability may be exploited to conduct a denial of proper service for legitimate users.
Attackers may leverage this issue to prevent the software from completing file scans, for files received subsequent to an attack. This may allow the attacker to bypass Anti-Virus scans.
Sophos Anti-Virus is prone to a remote denial of service vulnerability when it is configured to 'Scan inside archive files'. This is not a default setting.
The issue exists due to failure of the software to adequately sanitize 'Extra field length' values contained in BZip2 archives. Ultimately this vulnerability may be exploited to conduct a denial of proper service for legitimate users.
Attackers may leverage this issue to prevent the software from completing file scans, for files received subsequent to an attack. This may allow the attacker to bypass Anti-Virus scans.
Exploit / POC
Sophos Anti-Virus BZip2 Archive Handling Remote Denial Of Service Vulnerability
The following proof of concept is available; the proof of concept is a hex-dump of an archive that can be used to trigger the issue:
The following proof of concept is available; the proof of concept is a hex-dump of an archive that can be used to trigger the issue:
Solution / Fix
Sophos Anti-Virus BZip2 Archive Handling Remote Denial Of Service Vulnerability
Solution:
The vendor has released updates to address this issue. These updates may be automatically applied by customers that are using the EM Library.
Additionally, these updates may be manually retrieved from the following location:
http://www.sophos.com/support/updates
Solution:
The vendor has released updates to address this issue. These updates may be automatically applied by customers that are using the EM Library.
Additionally, these updates may be manually retrieved from the following location:
http://www.sophos.com/support/updates
References
Sophos Anti-Virus BZip2 Archive Handling Remote Denial Of Service Vulnerability
References:
References:
- Sophos Homepage (Sophos)
- iDEFENSE Security Advisory 07.14.05: Sophos Anti-Virus Zip File Handling DoS Vul ("iDEFENSE Labs"
)