Multiple Vendor File Scanner Malicious Archive DoS Vulnerability
BID:3027
Info
Multiple Vendor File Scanner Malicious Archive DoS Vulnerability
| Bugtraq ID: | 3027 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2001 12:00AM |
| Updated: | Jul 12 2001 12:00AM |
| Credit: | First discussed in vuln-dev mailing list in a thread started by Michel Arboi < [email protected] > on June 18, 2001. |
| Vulnerable: |
F-Secure Anti-Virus 5.2.1 F-Secure Anti-Virus 5.0.2 Baltimore Technologies MAILsweeper for SMTP 4.2.1 |
| Not Vulnerable: |
Sophos Anti-Virus 3.4.6 McAfee WebShield SMTP 4.5 McAfee VirusScan 4.5 McAfee VirusScan 4.0.3 McAfee Agent ASaP VirusScan 1.0 |
Solution / Fix
Multiple Vendor File Scanner Malicious Archive DoS Vulnerability
Solution:
Baltimore Technologies has acknowledged this issue, and has reported that MAILsweeper installed on a machine with a single partition is subject to this issue. MAILsweeper configured to use multiple partitions moves the message to a quarantine area once the free space is exhausted. During this process messages will continue to be received and delivered. Baltimore Technologies has released a document (Potential Threat from the â??Zip of Deathâ?) demonstrating the required steps to take in order to mitigate this issue. Please see the reference section to obtain the document
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Baltimore Technologies has acknowledged this issue, and has reported that MAILsweeper installed on a machine with a single partition is subject to this issue. MAILsweeper configured to use multiple partitions moves the message to a quarantine area once the free space is exhausted. During this process messages will continue to be received and delivered. Baltimore Technologies has released a document (Potential Threat from the â??Zip of Deathâ?) demonstrating the required steps to take in order to mitigate this issue. Please see the reference section to obtain the document
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Multiple Vendor File Scanner Malicious Archive DoS Vulnerability
References:
References:
- John Leyden: DoS risk from Zip of death attacks on AV software? (The Register)
- Potential Threat from the �??Zip of Death�?� (Baltimore Technologies)