Multiple Vendor bzip2 Antivirus Software Denial of Service Vulnerability
BID:9393
Info
Multiple Vendor bzip2 Antivirus Software Denial of Service Vulnerability
| Bugtraq ID: | 9393 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 09 2004 12:00AM |
| Updated: | Jan 09 2004 12:00AM |
| Credit: | The disclosure of this issue has been credited to Dr. Peter Bieringer, Steve Wray, Harald Geiger, and Ralf Hildebrandt. |
| Vulnerable: |
Trend Micro InterScan VirusWall 3.8 Build 1130 McAfee VirusScan for Linux 4.16 Kaspersky Labs Kaspersky Antivirus for Linux Servers 5.0.1 .0 AMaViS amavisd-snapshot-20020531 AMaViS amavisd-snapshot-20020300 AMaViS amavisd 0.1 AMaViS AMaViS 0.3.12 pre8 AMaViS AMaViS 0.3.12 pre7 AMaViS AMaViS 0.3.12 pre6 AMaViS AMaViS 0.3.12 AMaViS AMaViS 0.2 pre-5 AMaViS AMaViS 0.2 pre-4 AMaViS AMaViS 0.2 -pre6-20000704 AMaViS AMaViS 0.2 -pre6-20000604 |
| Not Vulnerable: |
AMaViS amavisd-new-20021116 |
Discussion
Multiple Vendor bzip2 Antivirus Software Denial of Service Vulnerability
Multiple vendor antivirus software applications have been reported to be prone to a denial of service vulnerability. This issue presents itself when an affected application attempts to decompress an excessively large bzip2 archive.
Kaspersky AntiVirus for Linux 5.0.1.0, Trend Micro InterScan VirusWall 3.8 Build 1130, and McAfee Virus Scan for Linux v4.16.0 have been reported to be prone to this issue, however, it is likely that other products are affected as well. It has been reported that some versions of AMaViS including 0.2.x/0.3.x and amavisd prior to amavisd-new-20021116 may be affected by this issue as well.
Further information indicates that this issue is not limited to bzip2 and may also affect other compression technologies. The discoverers of this issue have indicated that decompression bombs have been created for bzip2, gzip, zip, mime-embedded bombs, png and gif graphics, and openoffice zip.
Multiple vendor antivirus software applications have been reported to be prone to a denial of service vulnerability. This issue presents itself when an affected application attempts to decompress an excessively large bzip2 archive.
Kaspersky AntiVirus for Linux 5.0.1.0, Trend Micro InterScan VirusWall 3.8 Build 1130, and McAfee Virus Scan for Linux v4.16.0 have been reported to be prone to this issue, however, it is likely that other products are affected as well. It has been reported that some versions of AMaViS including 0.2.x/0.3.x and amavisd prior to amavisd-new-20021116 may be affected by this issue as well.
Further information indicates that this issue is not limited to bzip2 and may also affect other compression technologies. The discoverers of this issue have indicated that decompression bombs have been created for bzip2, gzip, zip, mime-embedded bombs, png and gif graphics, and openoffice zip.
Exploit / POC
Multiple Vendor bzip2 Antivirus Software Denial of Service Vulnerability
No exploit is required.
Example bzip2 archives may be downloaded from the following location:
ftp://ftp.aerasec.de/pub/advisories/bzip2bomb/
No exploit is required.
Example bzip2 archives may be downloaded from the following location:
ftp://ftp.aerasec.de/pub/advisories/bzip2bomb/
Solution / Fix
Multiple Vendor bzip2 Antivirus Software Denial of Service Vulnerability
Solution:
AMaViS has released an advisory with information about this issue affecting AMaViS products. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
AMaViS has released an advisory with information about this issue affecting AMaViS products. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Multiple Vendor bzip2 Antivirus Software Denial of Service Vulnerability
References:
References:
- Amavis Project Homepage (Amavis)
- AMaViS Security Announcement ASA-2004-1 (AMaViS)
- Antivirus DoS (Dr. Peter Bieringer)
- Possible Denial-of-Service caused by bzip2 bomb (AERA Network Security)
- Decompression Bombs (Matthias Leu
)