[NT] HAURI Anti-Virus ALZ Archive Handling Buffer Overflow

From: SecuriTeam (support_at_securiteam.com)
Date: 10/10/05

  • Next message: SecuriTeam: "[NT] Webroot Desktop Firewall Two Vulnerabilities"
    To: list@securiteam.com
    Date: 10 Oct 2005 13:54:42 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      HAURI Anti-Virus ALZ Archive Handling Buffer Overflow
    ------------------------------------------------------------------------

    SUMMARY

     <http://www.hauri.net/> HAURI offers "virus detection software (ViRobot)
    for servers (Windows/Unix), mail gateways (Domino/Exchange) and desktop
    (Windows) environments".

    Secunia Research has discovered a vulnerability in various HAURI
    anti-virus products, which can be exploited by malicious people to
    compromise a vulnerable system.

    DETAILS

    Vulnerable Systems:
     * ViRobot Expert 4.0
     * ViRobot Advanced Server
     * HAURI LiveCall

    With vrAZMain.dll version 5.8.22.137

    Immune Systems:
     * vrAZMain.dll version 5.9.22.154

    The vulnerability is caused due to a boundary error in the archive
    decompression library when reading the filename of a compressed file from
    an ALZ archive. This can be exploited to cause a stack-based buffer
    overflow when a malicious ALZ archive is scanned.

    Successful exploitation allows arbitrary code execution, but requires that
    compressed file scanning is enabled.

    Solution:

    Apply updates.

    ViRobot Expert 4.0 / ViRobot Advanced Server:
    Update to the latest version via online update. (vrAZMain.dll version
    5.9.22.154)

    HAURI LiveCall:
    Update to the latest version by visiting the vendor's LiveCall website.
    (vrAZMain.dll version 5.9.22.154)

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:vuln@secunia.com> Secunia
    Research.
    The original article can be found at:
    <http://secunia.com/secunia_research/2005-47/advisory/>
    http://secunia.com/secunia_research/2005-47/advisory/

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[NT] Webroot Desktop Firewall Two Vulnerabilities"

    Relevant Pages

    • [UNIX] MPlayer MMST and Real RTSP Multiple Heap Overflows
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The second vulnerability is due to a heap overflow ... which may be exploited via a malicious server to ... cause a denial of service and potentially compromise a vulnerable system. ...
      (Securiteam)
    • [EXPL] FRB Remote Command Execution (Exploit)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... attackers to execute arbitrary code on the vulnerable system, ... print $sock "Host: $host\n"; ...
      (Securiteam)
    • [UNIX] Mathopd Insecure Dump File Creation
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Mathopd supports useful features of HTTP/1.1, ... vulnerable system. ... the system with the privileges of the user running Mathopd. ...
      (Securiteam)
    • [NT] AVIRA Antivirus ACE Archive Handling Buffer Overflow
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... compromise a vulnerable system. ... Successful exploitation allows arbitrary code execution, ... The vendor has issue the following statement: ...
      (Securiteam)
    • [NT] MailEnable POP Service "PASS" Command Buffer Overflow
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... MailEnable POP Service "PASS" Command Buffer Overflow ... be exploited by malicious people to compromise a vulnerable system. ... Successful exploitation allows execution of arbitrary code. ...
      (Securiteam)