Kaspersky Anti-Virus Engine CHM File Parser Remote Buffer Overflow Vulnerability
BID:15054
Info
Kaspersky Anti-Virus Engine CHM File Parser Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 15054 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-2937 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2005 12:00AM |
| Updated: | Jul 12 2009 05:07PM |
| Credit: | Discovery is credited to an anonymous researcher. |
| Vulnerable: |
Kaspersky Labs Kaspersky Antivirus for Linux Servers 5.0.5 Kaspersky Labs AntiVirus for Linux Workstations 5.0.5 Kaspersky Labs Anti-Virus Personal 5.0.227 F-Secure Anti-Virus For Linux 4.5 |
| Not Vulnerable: | |
Discussion
Kaspersky Anti-Virus Engine CHM File Parser Remote Buffer Overflow Vulnerability
Kaspersky Anti-Virus Engine is prone to a remote buffer overflow vulnerability.
This issue presents itself when an attacker sends a maliciously crafted CHM file to an affected computer and this file is processed by Kaspersky's CHM file parser.
This vulnerability allows attackers to execute arbitrary machine code in the context of the affected application. Attackers may gain privileged remote access to computers running the affected application.
Kaspersky Anti-Virus Engine is prone to a remote buffer overflow vulnerability.
This issue presents itself when an attacker sends a maliciously crafted CHM file to an affected computer and this file is processed by Kaspersky's CHM file parser.
This vulnerability allows attackers to execute arbitrary machine code in the context of the affected application. Attackers may gain privileged remote access to computers running the affected application.
Exploit / POC
Kaspersky Anti-Virus Engine CHM File Parser Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Kaspersky Anti-Virus Engine CHM File Parser Remote Buffer Overflow Vulnerability
Solution:
The vendor has released a signature update to address this issue. Users with updated signatures released after July 2005 are not vulnerable.
Solution:
The vendor has released a signature update to address this issue. Users with updated signatures released after July 2005 are not vulnerable.
References
Kaspersky Anti-Virus Engine CHM File Parser Remote Buffer Overflow Vulnerability
References:
References:
- Kaspersky Antivirus Homepage (Kaspersky Labs)
- Kaspersky Anti-Virus Engine CHM File Parser Buffer Overflow Vulnerability (iDEFENSE Labs
)