ClamAV CAB File Remote Denial of Service Vulnerability
BID:22580
Info
ClamAV CAB File Remote Denial of Service Vulnerability
| Bugtraq ID: | 22580 |
| Class: | Design Error |
| CVE: |
CVE-2007-0897 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 15 2007 12:00AM |
| Updated: | Mar 19 2008 02:00AM |
| Credit: | The discoverer of this issue wishes to remain anonymous. |
| Vulnerable: |
SuSE Linux Enterprise Server 9 SuSE Linux Enterprise Server 10 SuSE Linux 9.3 x86-64 SuSE Linux 9.3 x86 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc SuSE Linux 10.0 x86-64 SuSE Linux 10.0 x86 SuSE Linux 10.0 ppc S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 10.1 Pardus Linux 2007.1 Mandriva Linux Mandrake 2006.0 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 ifenslave ifenslave 0.88 Gentoo app-antivirus/clamav 0.88.6 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Cosmicperl Directory Pro 10.0.3 Clam Anti-Virus ClamAV 0.88.5 Clam Anti-Virus ClamAV 0.88.4 Clam Anti-Virus ClamAV 0.88.3 Clam Anti-Virus ClamAV 0.88.2 Clam Anti-Virus ClamAV 0.88.1 Clam Anti-Virus ClamAV 0.87.1 Clam Anti-Virus ClamAV 0.87 -1 Clam Anti-Virus ClamAV 0.87 Clam Anti-Virus ClamAV 0.86.2 Clam Anti-Virus ClamAV 0.86 .1 Clam Anti-Virus ClamAV 0.86 Clam Anti-Virus ClamAV 0.85.1 Clam Anti-Virus ClamAV 0.85 Clam Anti-Virus ClamAV 0.84 rc2 Clam Anti-Virus ClamAV 0.84 rc1 Clam Anti-Virus ClamAV 0.84 Clam Anti-Virus ClamAV 0.83 Clam Anti-Virus ClamAV 0.82 Clam Anti-Virus ClamAV 0.81 Clam Anti-Virus ClamAV 0.80 rc4 Clam Anti-Virus ClamAV 0.80 rc3 Clam Anti-Virus ClamAV 0.80 rc2 Clam Anti-Virus ClamAV 0.80 rc1 Clam Anti-Virus ClamAV 0.80 Clam Anti-Virus ClamAV 0.75.1 Clam Anti-Virus ClamAV 0.70 Clam Anti-Virus ClamAV 0.68 -1 Clam Anti-Virus ClamAV 0.68 Clam Anti-Virus ClamAV 0.67 Clam Anti-Virus ClamAV 0.65 Clam Anti-Virus ClamAV 0.60 Clam Anti-Virus ClamAV 0.54 Clam Anti-Virus ClamAV 0.53 Clam Anti-Virus ClamAV 0.52 Clam Anti-Virus ClamAV 0.51 Clam Anti-Virus ClamAV 0.88.6 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.3.9 Apple Mac OS X Server 10.3.8 Apple Mac OS X Server 10.3.7 Apple Mac OS X Server 10.3.6 Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.3.3 Apple Mac OS X Server 10.3.2 Apple Mac OS X Server 10.3.1 Apple Mac OS X Server 10.3 Apple Mac OS X Server 10.2.8 Apple Mac OS X Server 10.2.7 Apple Mac OS X Server 10.2.6 Apple Mac OS X Server 10.2.5 Apple Mac OS X Server 10.2.4 Apple Mac OS X Server 10.2.3 Apple Mac OS X Server 10.2.2 Apple Mac OS X Server 10.2.1 Apple Mac OS X Server 10.2 Apple Mac OS X Server 10.1.5 Apple Mac OS X Server 10.1.4 Apple Mac OS X Server 10.1.3 Apple Mac OS X Server 10.1.2 Apple Mac OS X Server 10.1.1 Apple Mac OS X Server 10.1 Apple Mac OS X Server 10.0 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.3.9 Apple Mac OS X 10.3.8 Apple Mac OS X 10.3.7 Apple Mac OS X 10.3.6 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.3.3 Apple Mac OS X 10.3.2 Apple Mac OS X 10.3.1 Apple Mac OS X 10.3 Apple Mac OS X 10.2.8 Apple Mac OS X 10.2.7 Apple Mac OS X 10.2.6 Apple Mac OS X 10.2.5 Apple Mac OS X 10.2.4 Apple Mac OS X 10.2.3 Apple Mac OS X 10.2.2 Apple Mac OS X 10.2.1 Apple Mac OS X 10.2 Apple Mac OS X 10.1.5 Apple Mac OS X 10.1.4 Apple Mac OS X 10.1.3 Apple Mac OS X 10.1.2 Apple Mac OS X 10.1.1 Apple Mac OS X 10.1 Apple Mac OS X 10.1 Apple Mac OS X 10.0.4 Apple Mac OS X 10.0.3 Apple Mac OS X 10.0.2 Apple Mac OS X 10.0.1 Apple Mac OS X 10.0 3 Apple Mac OS X 10.0 Apple Mac OS X 10.5 |
| Not Vulnerable: |
Gentoo app-antivirus/clamav 0.90 Clam Anti-Virus ClamAV 0.90 |
Discussion
ClamAV CAB File Remote Denial of Service Vulnerability
ClamAV is prone to a denial-of-service vulnerability.
An attacker can exploit this vulnerability to prevent the software from scanning certain types of data. When it encounters the data, the application will reject it. This can result in denial-of-service conditions.
Versions prior to ClamAV 0.90 stable are vulnerable.
ClamAV is prone to a denial-of-service vulnerability.
An attacker can exploit this vulnerability to prevent the software from scanning certain types of data. When it encounters the data, the application will reject it. This can result in denial-of-service conditions.
Versions prior to ClamAV 0.90 stable are vulnerable.
Exploit / POC
ClamAV CAB File Remote Denial of Service Vulnerability
An attacker can exploit this issue by sending specially crafted CAB files to a vulnerable computer.
An attacker can exploit this issue by sending specially crafted CAB files to a vulnerable computer.
Solution / Fix
ClamAV CAB File Remote Denial of Service Vulnerability
Solution:
The vendor has released version 0.90 to address this issue. Please see the references for more information.
SuSE Linux 10.1 x86-64
SuSE Linux 10.1 x86
Clam Anti-Virus ClamAV 0.53
Clam Anti-Virus ClamAV 0.65
Clam Anti-Virus ClamAV 0.70
Clam Anti-Virus ClamAV 0.80
Clam Anti-Virus ClamAV 0.80 rc1
Clam Anti-Virus ClamAV 0.80 rc2
Clam Anti-Virus ClamAV 0.81
Clam Anti-Virus ClamAV 0.82
Clam Anti-Virus ClamAV 0.84 rc1
Clam Anti-Virus ClamAV 0.85
Clam Anti-Virus ClamAV 0.85.1
Clam Anti-Virus ClamAV 0.86 .1
Clam Anti-Virus ClamAV 0.86.2
Clam Anti-Virus ClamAV 0.87
Clam Anti-Virus ClamAV 0.87 -1
ifenslave ifenslave 0.88
Clam Anti-Virus ClamAV 0.88.2
Clam Anti-Virus ClamAV 0.88.3
Clam Anti-Virus ClamAV 0.88.5
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.4.11
Apple Mac OS X 10.5.2
Apple Mac OS X Server 10.5.2
Solution:
The vendor has released version 0.90 to address this issue. Please see the references for more information.
SuSE Linux 10.1 x86-64
-
SuSE clamav-0.90-0.2.x86_64.rpm
SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/x86_64/clamav-0.90-0.2.x86 _64.rpm
SuSE Linux 10.1 x86
-
SuSE clamav-0.90-0.2.i586.rpm
SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/clamav-0.90-0.2.i586. rpm
Clam Anti-Virus ClamAV 0.53
-
Clam Anti-Virus clamav-0.90.tar.gz
http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.90.tar.gz
Clam Anti-Virus ClamAV 0.65
-
Clam Anti-Virus clamav-0.90.tar.gz
http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.90.tar.gz
Clam Anti-Virus ClamAV 0.70
-
Clam Anti-Virus clamav-0.90.tar.gz
http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.90.tar.gz
Clam Anti-Virus ClamAV 0.80
-
Clam Anti-Virus clamav-0.90.tar.gz
http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.90.tar.gz
Clam Anti-Virus ClamAV 0.80 rc1
-
Clam Anti-Virus clamav-0.90.tar.gz
http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.90.tar.gz
Clam Anti-Virus ClamAV 0.80 rc2
-
Clam Anti-Virus clamav-0.90.tar.gz
http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.90.tar.gz
Clam Anti-Virus ClamAV 0.81
-
Clam Anti-Virus clamav-0.90.tar.gz
http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.90.tar.gz
Clam Anti-Virus ClamAV 0.82
-
Clam Anti-Virus clamav-0.90.tar.gz
http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.90.tar.gz
Clam Anti-Virus ClamAV 0.84 rc1
-
Clam Anti-Virus clamav-0.90.tar.gz
http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.90.tar.gz
Clam Anti-Virus ClamAV 0.85
-
Clam Anti-Virus clamav-0.90.tar.gz
http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.90.tar.gz
Clam Anti-Virus ClamAV 0.85.1
-
Clam Anti-Virus clamav-0.90.tar.gz
http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.90.tar.gz
Clam Anti-Virus ClamAV 0.86 .1
-
Clam Anti-Virus clamav-0.90.tar.gz
http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.90.tar.gz
Clam Anti-Virus ClamAV 0.86.2
-
Clam Anti-Virus clamav-0.90.tar.gz
http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.90.tar.gz
Clam Anti-Virus ClamAV 0.87
-
Clam Anti-Virus clamav-0.90.tar.gz
http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.90.tar.gz -
Mandriva clamav-0.90-0.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download -
Mandriva clamav-0.90-0.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva clamav-0.90-0.1.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva clamav-0.90-0.1.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva clamav-db-0.90-0.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download -
Mandriva clamav-db-0.90-0.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva clamav-db-0.90-0.1.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva clamav-db-0.90-0.1.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva clamav-milter-0.90-0.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download -
Mandriva clamav-milter-0.90-0.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva clamav-milter-0.90-0.1.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva clamav-milter-0.90-0.1.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva clamd-0.90-0.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download -
Mandriva clamd-0.90-0.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva clamd-0.90-0.1.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva clamd-0.90-0.1.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva lib64clamav1-0.90-0.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva lib64clamav1-0.90-0.1.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva lib64clamav1-devel-0.90-0.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva lib64clamav1-devel-0.90-0.1.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva libclamav1-0.90-0.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download -
Mandriva libclamav1-0.90-0.1.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva libclamav1-devel-0.90-0.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download -
Mandriva libclamav1-devel-0.90-0.1.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
Clam Anti-Virus ClamAV 0.87 -1
-
Clam Anti-Virus clamav-0.90.tar.gz
http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.90.tar.gz
ifenslave ifenslave 0.88
-
Clam Anti-Virus clamav-0.90.tar.gz
http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.90.tar.gz
Clam Anti-Virus ClamAV 0.88.2
-
Clam Anti-Virus clamav-0.90.tar.gz
http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.90.tar.gz
Clam Anti-Virus ClamAV 0.88.3
-
Clam Anti-Virus clamav-0.90.tar.gz
http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.90.tar.gz
Clam Anti-Virus ClamAV 0.88.5
-
Clam Anti-Virus clamav-0.90.tar.gz
http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.90.tar.gz
Apple Mac OS X 10.4.11
-
Apple SecUpd2008-002PPC.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002PPC.dmg -
Apple SecUpd2008-002Univ.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002Univ.dmg
Apple Mac OS X Server 10.4.11
-
Apple SecUpdSrvr2008-002PPC.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpdSrvr2008-002PPC.dmg -
Apple SecUpdSrvr2008-002Univ.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpdSrvr2008-002Univ.dmg
Apple Mac OS X 10.5.2
-
Apple SecUpd2008-002.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002.dmg
Apple Mac OS X Server 10.5.2
References
ClamAV CAB File Remote Denial of Service Vulnerability
References:
References:
- ClamAV Homepage (ClamAV)
- Multiple Vendor ClamAV CAB File Denial of Service Vulnerability (iDefense Labs)
- Multiple Vendor ClamAV CAB File Denial of Service Vulnerability (iDefense Labs)