Multiple Vendor bzip2 Antivirus Software Denial of Service Vulnerability

BID:9393

Info

Multiple Vendor bzip2 Antivirus Software Denial of Service Vulnerability

Bugtraq ID: 9393
Class: Failure to Handle Exceptional Conditions
CVE:
Remote: Yes
Local: No
Published: Jan 09 2004 12:00AM
Updated: Jan 09 2004 12:00AM
Credit: The disclosure of this issue has been credited to Dr. Peter Bieringer, Steve Wray, Harald Geiger, and Ralf Hildebrandt.
Vulnerable: Trend Micro InterScan VirusWall 3.8 Build 1130
McAfee VirusScan for Linux 4.16
Kaspersky Labs Kaspersky Antivirus for Linux Servers 5.0.1 .0
AMaViS amavisd-snapshot-20020531
AMaViS amavisd-snapshot-20020300
AMaViS amavisd 0.1
AMaViS AMaViS 0.3.12 pre8
AMaViS AMaViS 0.3.12 pre7
AMaViS AMaViS 0.3.12 pre6
AMaViS AMaViS 0.3.12
AMaViS AMaViS 0.2 pre-5
AMaViS AMaViS 0.2 pre-4
AMaViS AMaViS 0.2 -pre6-20000704
AMaViS AMaViS 0.2 -pre6-20000604
Not Vulnerable: AMaViS amavisd-new-20021116

Discussion

Multiple Vendor bzip2 Antivirus Software Denial of Service Vulnerability

Multiple vendor antivirus software applications have been reported to be prone to a denial of service vulnerability. This issue presents itself when an affected application attempts to decompress an excessively large bzip2 archive.

Kaspersky AntiVirus for Linux 5.0.1.0, Trend Micro InterScan VirusWall 3.8 Build 1130, and McAfee Virus Scan for Linux v4.16.0 have been reported to be prone to this issue, however, it is likely that other products are affected as well. It has been reported that some versions of AMaViS including 0.2.x/0.3.x and amavisd prior to amavisd-new-20021116 may be affected by this issue as well.

Further information indicates that this issue is not limited to bzip2 and may also affect other compression technologies. The discoverers of this issue have indicated that decompression bombs have been created for bzip2, gzip, zip, mime-embedded bombs, png and gif graphics, and openoffice zip.

Exploit / POC

Multiple Vendor bzip2 Antivirus Software Denial of Service Vulnerability

No exploit is required.

Example bzip2 archives may be downloaded from the following location:

ftp://ftp.aerasec.de/pub/advisories/bzip2bomb/

Solution / Fix

Multiple Vendor bzip2 Antivirus Software Denial of Service Vulnerability

Solution:
AMaViS has released an advisory with information about this issue affecting AMaViS products. Please see the referenced advisory for more information.

Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

References

Multiple Vendor bzip2 Antivirus Software Denial of Service Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report