RETIRED: ClamAV 'libclamav/pe.c' UPACK File Heap Based Buffer Overflow Vulnerability
BID:28783
Info
RETIRED: ClamAV 'libclamav/pe.c' UPACK File Heap Based Buffer Overflow Vulnerability
| Bugtraq ID: | 28783 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1100 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2008 12:00AM |
| Updated: | Apr 18 2008 12:27AM |
| Credit: | Alin Rad Pop, Secunia Research |
| Vulnerable: |
Clam Anti-Virus ClamAV 0.92.1 Clam Anti-Virus ClamAV 0.92 |
| Not Vulnerable: |
Clam Anti-Virus ClamAV 0.93 |
Discussion
RETIRED: ClamAV 'libclamav/pe.c' UPACK File Heap Based Buffer Overflow Vulnerability
ClamAV is prone to a heap-based buffer-overflow vulnerability because it fails to properly verify user-supplied data.
Successful exploits of this vulnerability can allow remote attackers to execute arbitrary machine code in the context of applications using the vulnerable 'libclamav' library. Failed exploit attempts will likely cause denial-of-service conditions.
ClamAV 0.92 and 0.92.1 are vulnerable to this issue; other versions may also be affected.
NOTE: This BID is being retired because it is a duplicate of BID 28756.
ClamAV is prone to a heap-based buffer-overflow vulnerability because it fails to properly verify user-supplied data.
Successful exploits of this vulnerability can allow remote attackers to execute arbitrary machine code in the context of applications using the vulnerable 'libclamav' library. Failed exploit attempts will likely cause denial-of-service conditions.
ClamAV 0.92 and 0.92.1 are vulnerable to this issue; other versions may also be affected.
NOTE: This BID is being retired because it is a duplicate of BID 28756.
Exploit / POC
RETIRED: ClamAV 'libclamav/pe.c' UPACK File Heap Based Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RETIRED: ClamAV 'libclamav/pe.c' UPACK File Heap Based Buffer Overflow Vulnerability
Solution:
Reports indicate that the vendor initially addressed this issue by remotely switching off the PE scanning module after 10/03/2008, but Symantec has not confirmed this. Please contact the vendor for information on final fixes and update procedures.
UPDATE: The vendor released ClamAV 0.93 to address this issue.
NOTE: This BID is being retired because it is a duplicate of BID 28756.
Solution:
Reports indicate that the vendor initially addressed this issue by remotely switching off the PE scanning module after 10/03/2008, but Symantec has not confirmed this. Please contact the vendor for information on final fixes and update procedures.
UPDATE: The vendor released ClamAV 0.93 to address this issue.
NOTE: This BID is being retired because it is a duplicate of BID 28756.
References
RETIRED: ClamAV 'libclamav/pe.c' UPACK File Heap Based Buffer Overflow Vulnerability
References:
References:
- ClamAV Homepage (Clam Anti-Virus)
- ClamAV Upack Processing Buffer Overflow Vulnerability (Secunia Research)