Clam Anti-Virus ClamAV UPX Compressed PE File Heap Buffer Overflow Vulnerability
BID:19381
CVE-2006-4018 |Info
Clam Anti-Virus ClamAV UPX Compressed PE File Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 19381 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-4018 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 07 2006 12:00AM |
| Updated: | Jan 16 2007 11:00PM |
| Credit: | Damian Put <[email protected]> discovered this issue. |
| Vulnerable: |
Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 SuSE Linux Enterprise Server 9 SuSE Linux Enterprise Server 10 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 10.1 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Gentoo Linux Debian Linux 3.1 Clam Anti-Virus ClamAV 0.88.3 Clam Anti-Virus ClamAV 0.88.2 |
| Not Vulnerable: |
Clam Anti-Virus ClamAV 0.88.4 |
Discussion
Clam Anti-Virus ClamAV UPX Compressed PE File Heap Buffer Overflow Vulnerability
ClamAV is prone to a heap buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
This issue occurs when the application attempts to handle compressed UPX files.
Exploiting this issue could allow attacker-supplied machine code to execute in the context of the affected application. The issue would occur when the malformed file is scanned manually or automatically in deployments such as email gateways.
ClamAV versions 0.88.2 and 0.88.3 are vulnerable to this issue; prior versions may also be affected.
ClamAV is prone to a heap buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.
This issue occurs when the application attempts to handle compressed UPX files.
Exploiting this issue could allow attacker-supplied machine code to execute in the context of the affected application. The issue would occur when the malformed file is scanned manually or automatically in deployments such as email gateways.
ClamAV versions 0.88.2 and 0.88.3 are vulnerable to this issue; prior versions may also be affected.
Exploit / POC
Clam Anti-Virus ClamAV UPX Compressed PE File Heap Buffer Overflow Vulnerability
The following '.EXE' file reportedly demonstrates this issue. Symantec has neither tested nor verified the file. Users should take all sufficient precautions when handling this potentially malicious file.
The following '.EXE' file reportedly demonstrates this issue. Symantec has neither tested nor verified the file. Users should take all sufficient precautions when handling this potentially malicious file.
Solution / Fix
Clam Anti-Virus ClamAV UPX Compressed PE File Heap Buffer Overflow Vulnerability
Solution:
The vendor has released version 0.88.4 of ClamAV to address this issue.
Please see the referenced advisories for more information.
Clam Anti-Virus ClamAV 0.88.2
Clam Anti-Virus ClamAV 0.88.3
Solution:
The vendor has released version 0.88.4 of ClamAV to address this issue.
Please see the referenced advisories for more information.
Clam Anti-Virus ClamAV 0.88.2
-
Clam Anti-Virus clamav-0.88.4.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.4.tar.gz?downloa d
Clam Anti-Virus ClamAV 0.88.3
-
Clam Anti-Virus clamav-0.88.4.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.4.tar.gz?downloa d
References
Clam Anti-Virus ClamAV UPX Compressed PE File Heap Buffer Overflow Vulnerability
References:
References:
- ClamAV Homepage (Clam Anti-Virus)