[UNIX] Clam AntiVirus ClamAV CHM Chunk Name Length DoS



The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html

- - - - - - - - -



Clam AntiVirus ClamAV CHM Chunk Name Length DoS
------------------------------------------------------------------------


SUMMARY

<http://clamav.net/> Clam AntiVirus is "a multi-platform GPL anti-virus
toolkit. The main purpose of which is integration into electronic mail
servers". Microsoft Compressed HTML Help (CHM) files are commonly used for
windows based software documentation. Remote exploitation of a input
validation vulnerability in Clam AntiVirus's ClamAV could allow attackers
to crash the virus scanning service.

DETAILS

Vulnerable Systems:
* Clam AntiVirus ClamAV version 0.88.4

Immune Systems:
* Clam AntiVirus ClamAV version 0.88.5

The vulnerability specifically exists due to improper handling of an
specially crafted CHM file. While processing such a file, ClamAV may
attempt to read an invalid memory location resulting in abnormal
termination of the scanning service.

CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5295>
CVE-2006-5295

Disclosure Timeline:
09/28/2006 - Initial vendor notification
09/29/2006 - Initial vendor response
10/10/2006 - Second vendor notification
10/15/2006 - Coordinated public disclosure


ADDITIONAL INFORMATION

The information has been provided by
<mailto:idlabs-advisories@xxxxxxxxxxxx> iDefense Labs Security Advisories.
The original article can be found at:
<http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=423>
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=423



========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • [NT] Borland CaliberRM StarTeam Multicast Service Buffer Overflow Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Borland CaliberRM StarTeam Multicast Service Buffer Overflow Vulnerability ... 03/20/2007 - Initial vendor notification ...
    (Securiteam)
  • [UNIX] Hewlett Packard HP-UX Remote pfs_mountd.rpc Buffer Overflow Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Hewlett Packard HP-UX Remote pfs_mountd.rpc Buffer Overflow Vulnerability ... the attack is functional over UDP, thus allowing an attacker to completely ... 10/25/2004 Initial vendor notification ...
    (Securiteam)
  • [UNIX] Trend Micro VirusWall Buffer Overflow in VSAPI Library
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... buffer overflow vulnerability in VSAPI library allows arbitrary code ... is called "vscan" which is set suid root by default. ... permissions and thus granted all local users the privilege to execute the ...
    (Securiteam)
  • [UNIX] SCO Multiple Local Buffer Overflow
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Local exploitation of a buffer overflow vulnerability in the ppp binary, ... allows attackers to gain root privileges. ...
    (Securiteam)
  • [NT] Microsoft Word 6.0/95 Document Converter Buffer Overflow (MS04-041)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... WordPad is "a word processing application that uses the MFC rich edit ... Remote exploitation of a buffer overflow vulnerability in Microsoft ... Microsoft Word format files into the Rich Text Format natively handled by ...
    (Securiteam)