Frisk F-Prot Antivirus Command Line Scanner Buffer Overflow Vulnerability
BID:6969
Info
Frisk F-Prot Antivirus Command Line Scanner Buffer Overflow Vulnerability
| Bugtraq ID: | 6969 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 26 2003 12:00AM |
| Updated: | Feb 26 2003 12:00AM |
| Credit: | Discovery is credited to Knud Erik Højgaard <[email protected]>. |
| Vulnerable: |
Frisk Software F-Prot Antivirus for Linux and BSD 3.12 b |
| Not Vulnerable: |
Frisk Software F-Prot Antivirus for Linux and BSD 3.12 d |
Discussion
Frisk F-Prot Antivirus Command Line Scanner Buffer Overflow Vulnerability
Frisk's F-Prot Antivirus for Linux and BSD is prone to a buffer overflow in file name parameters that are passed to the command line scanner. If a backup script is launched by a privileged user to scan the filesystem scans a file with an unusually long name, arbitrary code could potentially execute on the system in the security context of the script's owner.
Frisk's F-Prot Antivirus for Linux and BSD is prone to a buffer overflow in file name parameters that are passed to the command line scanner. If a backup script is launched by a privileged user to scan the filesystem scans a file with an unusually long name, arbitrary code could potentially execute on the system in the security context of the script's owner.
Exploit / POC
Frisk F-Prot Antivirus Command Line Scanner Buffer Overflow Vulnerability
The following exploit code was provided by Knud Erik Højgaard <[email protected]>:
The following exploit code was provided by Knud Erik Højgaard <[email protected]>:
Solution / Fix
Frisk F-Prot Antivirus Command Line Scanner Buffer Overflow Vulnerability
Solution:
Frisk has fixed this issue in F-Prot Antivirus for Linux and BSD 3.12d. Users are advised to obtain upgrades at http://subscription.f-prot.com/download.html
Solution:
Frisk has fixed this issue in F-Prot Antivirus for Linux and BSD 3.12d. Users are advised to obtain upgrades at http://subscription.f-prot.com/download.html
References
Frisk F-Prot Antivirus Command Line Scanner Buffer Overflow Vulnerability
References:
References:
- F-Prot Update Center (Frisk Software)
- Fw: f-prot antivirus useless buffer overflow (Knud Erik Højgaard
) - Regarding F-Prot for Linux (F-Prot Antivirus Technical Support
)