ClamAV Multiple Insecure File Handling and Scanner Bypass Vulnerabilities
BID:27064
Info
ClamAV Multiple Insecure File Handling and Scanner Bypass Vulnerabilities
| Bugtraq ID: | 27064 |
| Class: | Unknown |
| CVE: |
CVE-2007-6595 CVE-2007-6596 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Dec 29 2007 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | Roflek and Lolek of TK53 discovered these issues. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Kolab Kolab Groupware Server 2.1 Kolab Kolab Groupware Server 2.0.4 Kolab Kolab Groupware Server 2.0.3 Kolab Kolab Groupware Server 2.0.2 Kolab Kolab Groupware Server 2.0.1 Kolab Kolab Groupware Server 2.2-rc1 Kolab Kolab Groupware Server 2.2 beta3 Kolab Kolab Groupware Server 2.2 beta1 Kolab Kolab Groupware Server 2.1beta2 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Clam Anti-Virus ClamAV 0.92 |
| Not Vulnerable: | |
Discussion
ClamAV Multiple Insecure File Handling and Scanner Bypass Vulnerabilities
ClamAV is prone to multiple vulnerabilities because it handles files in an insecure way and because it fails to scan certain files.
A successful attack may allow malicious users to perform symbolic-link attacks or to bypass scanning. Exploits may aid in further attacks.
ClamAV 0.92 is vulnerable to these issues; other versions may also be affected.
ClamAV is prone to multiple vulnerabilities because it handles files in an insecure way and because it fails to scan certain files.
A successful attack may allow malicious users to perform symbolic-link attacks or to bypass scanning. Exploits may aid in further attacks.
ClamAV 0.92 is vulnerable to these issues; other versions may also be affected.
Exploit / POC
ClamAV Multiple Insecure File Handling and Scanner Bypass Vulnerabilities
To exploit these issues, attackers can use with readily available utilities and may send email with malicous content.
To exploit these issues, attackers can use with readily available utilities and may send email with malicous content.
Solution / Fix
ClamAV Multiple Insecure File Handling and Scanner Bypass Vulnerabilities
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
References
ClamAV Multiple Insecure File Handling and Scanner Bypass Vulnerabilities
References:
References:
- ClamAV Homepage (Clam Anti-Virus)
- TK53 Advisory #2: Multiple vulnerabilities in ClamAV ("Lolek of TK53"
) - Kolab Security Issue 19 20080218 (Kolab)