n.runs AG - Management
 
 
n.runs AG
LEISTUNGSSPEKTRUM
IT INFRASTRUKTUR
IT SICHERHEIT SECURITY
IT BUSINESS CONSULTING
IT SOFTWARE

n.runs AG
Nassauer Straße 60
61440 Oberursel
Telefon: +49 (0) 6171/699-0
Telefax: +49 (0) 6171/699-199
E-mail: contact@nruns.com
Newsletter anfordern
Impressum

Anti-Virus Parsing Engines

Introduction
This is not a "Month of the Anti-Virus bugs" although it could have been; (though then, it would have been more adequate to call it "Month of the Parsing bugs"), all bugs that are going to be released will demonstrate what is seen by us as the weakest link within the security vendor industry: Parsing bugs

Watch this Space for more
About n.runs AG: Who we are Contact us link, Portofolio link, References link, Freeware Tools link
Click here to add an RSS FEED AddThis Social Bookmark Button


AVG Antivirus Divide by Zero - Denial of Service - 28/07/2008

A remotely exploitable vulnerability has been found in the files parsing engine. In detail, the following flaw was determined:

- A Denial of Service caused by a Divide by Zero while parsing UPX files.

Impact
This problem can lead to remote denial of service if an attacker carefully crafts a file that exploits the aforementioned vulnerability. The vulnerability is present in AVG Antivirus software versions prior to the program update AVG 8.0.156.

Vulnerable Products
   - AVG AntiVirus < 8.0.156

   d  Read more [txt link, html link]



FRISK (F-Prot) Out-of-Bound Memory Access Denial of Service (remote)- 16/07/2008

A remotely exploitable vulnerability has been found in the files' parsing engine. In detail, the following flaw was determined:

- DoS caused by an Out-of-Bound Memory Access while parsing CHM file's header: if the nb_dir field (Chunk number of root index chunk) value is set to 0xffffffff pointers math takes place and ends up in an out-of-bound read attempt.

Impact
This problem can lead to remote denial of service if an attacker carefully crafts a file that exploits the aforementioned vulnerability. The vulnerability is present in FRISK Anti-virus software mentioned above, in all platforms supported by the affected products prior to the engine Version 4.4.4.

Vulnerable Products
   - F-Prot Anti-Virus all platforms < 4.4.4

   d  Read more [txt link, html link]



Sophos Antivirus - Arbitrary Code Execution [UPX] UPDATE - 03/09/2007

A remotely exploitable vulnerability has been found in the file parsing engine. In detail, the following flaw was determined:

- One BYTE Overwrite in Arbritary Location caused by an Integer Handling issue while parsing the UPX format.

Impact
This problem can lead to remote denial of service or arbitrary code execution if an attacker carefully crafts a file that exploits the aforementioned vulnerability. The vulnerability is present in Sophos Anti-virus software listed above on all platforms supported by the affected products prior to the engine Version 2.48.0.

Vulnerable Products
- Sophos Anti-Virus for Windows Sophos Anti-Virus for Unix/Linux < 2.48.0

d Read more [txt link, pdf link, html link]



ClamAV Remote Code Execution - 03/09/2007

A remotely exploitable vulnerabilityhas been found in clamav-milter when used with sendmail. In detail, the following flaw was determined:

- Arbitrary code execution due to insecure call to popen()

Impact
This vulnerability can lead to remote code execution with root privileges. Leading to a complete compromise of the vulnerable system. An attacker can inject shell commands into the recipient field of sendmail, if clamav-milter was started with the black hole mode activated. The vulnerability is present in at least clamav version 0.91.1, prior versions may also be affected.

Vulnerable Products
- ClamAV, http://www.clamav.net

dRead more [ txt link, pdf link, html link]



Sophos Antivirus Denial of Service [GZIP] - 24/08/2007

A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Infinite Loop in GZip file parsing

Impact
This problem can lead to a remote Denial of Service (DoS) situation through high CPU consumption and exhaustion of storage resources if an attacker carefully crafts a file that exploits the aforementioned vulnerability. The vulnerability is present in Sophos Anti-virus software mentioned above on all platforms supported by the affected products prior to the engine Version 2.48.0.

Vulnerable Products
- Sophos Anti-Virus for Windows Sophos Anti-Virus for Unix/Linux < 2.48.0

dRead more [ txt link, pdf link, html link]



Computer Associates eTrust Antivirus Denial of Service [CHM]- 25/07/2007

A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined

- Infinite Loop in .CHM files parsing

Impact
This problem can lead to remote engine denial-of-service if an attacker carefully crafts a file that exploits the aforementioned vulnerability. The vulnerability is present in CA eTrust Antivirus software previous to file arclib.dll version 7.3.0.9.

Vulnerable Products
- CA eTrust Antivirus

dRead more [ txt link, pdf link, html link]



Norman Antivirus Denial of Service [DOC] - 23/07/2007

A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Divide by Zero in .DOC OLE2 file parsing

Impact
This problem can lead to remote engine denial of service if an attacker carefully crafts a file that exploits the aforementioned vulnerability. The vulnerability is present in Norman Antivirus software since at least version 5.90.

Vulnerable Products
- All Norman Antivirus Solutions

dRead more [ txt link, pdf link, html link]



Norman Antivirus Detection Bypass [DOC] - 23/07/2007

A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Detection Bypass through Integer Cast Around in .DOC OLE2 file parsing

Impact
This problem can lead to malicious code detection bypass if an attacker carefully crafts a file that exploits the aforementioned vulnerability. The vulnerability is present in Norman Antivirus software since at least version 5.90.

Vulnerable Products
- All Norman Antivirus Solutions

dRead more [ txt link, pdf link, html link]



Norman Antivirus Arbitrary Code Execution [LZH] - 23/07/2007

Multiple remotely exploitable vulnerabilities have been found in the file parsing engine. In detail, the following flaw was determined:

- 3 (Three) Buffer Overflow through Integer Cast Around in .LZH file parsing

Impact
These problems can lead to remote arbitrary code execution if an attacker carefully crafts a file that exploits any of the aforementioned vulnerabilities. The vulnerabilities are present in Norman Antivirus software since at least version 5.90.

Vulnerable Products
- All Norman Antivirus Solutions

dRead more [ txt link, pdf link, html link]



Norman Antivirus Arbitrary Code Execution [ACE] - 23/07/2007

A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Buffer Overflow through Integer Cast Around in .ACE file parsing

Impact
This problem can lead to remote arbitrary code execution if an attacker carefully crafts a file that exploits the aforementioned vulnerability. The vulnerability is present in Norman Antivirus software since at least version 5.90.

Vulnerable Products
- All Norman Antivirus Solutions

dRead more [ txt link, pdf link, html link]



Panda Antivirus Arbitrary Code Execution [EXE] - 20/07/2007

A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Buffer Overflow through Integer Cast Around in .EXE file parsing

Impact
This problem can lead to remote arbitrary code execution if an attacker carefully crafts a file that exploits the aforementioned vulnerability. The vulnerability is present in Panda Antivirus software versions prior to the last update of 20.Jul.2007.

Vulnerable Products
- Panda Antivirus

dRead more [ txt link, pdf link]



ESET NOD32 Denial of Service [ASPACK+FSG] - 20/07/2007

A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Divide by Zero in ASPACK and FSG packed files parsing

Impact
This problem can lead to remote denial of service if an attacker carefully crafts a file that exploits the aforementioned vulnerability. The vulnerability is present in NOD32 Antivirus software versions prior to the update v.2.2289.

Vulnerable Products
- ESET NOD32 Antivirus < v.2.2289

dRead more [ txt link, pdf link]



ESET NOD32 Denial of Service [ASPACK] - 20/07/2007

A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Infinite Loop through Integer Overflow in ASPACK packed files parsing

Impact
This problem can lead to remote denial of service provoked by high CPU consume and exhaustion of storage resource if an attacker carefully crafts a file that exploits the aforementioned vulnerability. The vulnerability is present in NOD32 Antivirus software versions prior to the update v.2.2289.

Vulnerable Products
- ESET NOD32 Antivirus < v.2.2289

dRead more [ txt link, pdf link]



ESET NOD32 Arbitrary Code Execution [CAB] - 20/07/2007

A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Heap Corruption through Race Condition in .CAB file parsing

Impact
This problem can lead to remote arbitrary code execution if an attacker carefully crafts a file that exploits the aforementioned vulnerability. The vulnerability is present in NOD32 Antivirus software versions prior to the update v.2.2289.

Vulnerable Products
- ESET NOD32 Antivirus < v.2.2289

dRead more [ txt link, pdf link]



F-Secure Denial of Service [FSG] - 04/06/2007
A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Infinite Loop in FSG Parsing

This problem can lead to a Denial of Service condition if an attacker carefully crafts a file that exploits the aforementioned vulnerability

Vulnerable Products
- F-Secure Anti-Virus for Workstations version 5.44 and earlier
- F-Secure Anti-Virus for Windows Servers version 5.52 and earlier
- F-Secure Anti-Virus for Citrix Servers version 5.52
- F-Secure Anti-Virus for MIMEsweeper version 5.61 and earlier
- F-Secure Anti-Virus Client Security version 6.03 and earlier
- F-Secure Anti-Virus for MS Exchange version 6.40 and earlier
- F-Secure Internet Gatekeeper version 6.60 and earlier
- F-Secure Internet Security 2005, 2006 and 2007
- F-Secure Anti-Virus 2005, 2006 and 2007 Solutions based on
- F-Secure Protection Service for Consumers version 6.40 and earlier
- F-Secure Anti-Virus for Linux Servers version 4.65 and earlier
- F-Secure Anti-Virus for Linux Gateways version 4.65 and earlier
- F-Secure Anti-Virus Linux Client Security 5.30 and earlier
- F-Secure Anti-Virus Linux Server Security 5.30 and earlier
- F-Secure Internet Gatekeeper for Linux 2.16 and earlier

dRead more [ txt link, pdf link, html link]



F-Secure Denial of Service [ARJ] - 04/06/2007
A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Infinite Loop in ARJ Parsing

This problem can lead to a Denial of Service condition if an attacker carefully crafts a file that exploits the aforementioned vulnerability

Vulnerable Products
- F-Secure Anti-Virus for Workstations version 5.44 and earlier
- F-Secure Anti-Virus for Windows Servers version 5.52 and earlier
- F-Secure Anti-Virus for Citrix Servers version 5.52
- F-Secure Anti-Virus for MIMEsweeper version 5.61 and earlier
- F-Secure Anti-Virus Client Security version 6.03 and earlier
- F-Secure Anti-Virus for MS Exchange version 6.40 and earlier
- F-Secure Internet Gatekeeper version 6.60 and earlier
- F-Secure Internet Security 2005, 2006 and 2007
- F-Secure Anti-Virus 2005, 2006 and 2007 Solutions based on
- F-Secure Protection Service for Consumers version 6.40 and earlier
- F-Secure Anti-Virus for Linux Servers version 4.65 and earlier
- F-Secure Anti-Virus for Linux Gateways version 4.65 and earlier
- F-Secure Anti-Virus Linux Client Security 5.30 and earlier
- F-Secure Anti-Virus Linux Server Security 5.30 and earlier
- F-Secure Internet Gatekeeper for Linux 2.16 and earlier

dRead more [ txt link, pdf link, html link]



F-Secure Remote Code Execution [LZH] - 01/06/2007
A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Buffer Overflow through Integer wrap around in .LZH files parsing

This problem can lead to remote arbitrary code execution if an attacker carefully crafts a file that exploits the aforementioned vulnerability

Vulnerable Products
- F-Secure Anti-Virus for Workstations version 5.44 and earlier
- F-Secure Anti-Virus for Windows Servers version 5.52 and earlier
- F-Secure Anti-Virus for Citrix Servers version 5.52
- F-Secure Anti-Virus for MIMEsweeper version 5.61 and earlier
- F-Secure Anti-Virus Client Security version 6.03 and earlier
- F-Secure Anti-Virus for MS Exchange version 6.40 and earlier
- F-Secure Internet Gatekeeper version 6.60 and earlier
- F-Secure Internet Security 2005, 2006 and 2007
- F-Secure Anti-Virus 2005, 2006 and 2007 Solutions based on
- F-Secure Protection Service for Consumers version 6.40 and earlier
- F-Secure Anti-Virus for Linux Servers version 4.65 and earlier
- F-Secure Anti-Virus for Linux Gateways version 4.65 and earlier
- F-Secure Anti-Virus Linux Client Security 5.30 and earlier
- F-Secure Anti-Virus Linux Server Security 5.30 and earlier
- F-Secure Internet Gatekeeper for Linux 2.16 and earlier

dRead more [ txt link, pdf link, html link]



Avira Antivir Denial of Service [TAR] - 30/05/2007
A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Infinite Loop in TAR Parsing

This problem can lead to remote arbitrary code execution if an attacker carefully crafts a file that exploits the aforementioned vulnerability

Vulnerable Products
- Avira Antivir <7.03.00.09

dRead more [ txt link, pdf link, html link]


Avira Antivir Denial of Service [UPX] - 29/05/2007
A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Divide by Zero in UPX packed files parsing

This problem can lead to remote arbitrary code execution if an attacker carefully crafts a file that exploits the aforementioned vulnerability

Vulnerable Products
- Avira Antivir <7.03.00.09

dRead more [ txt link, pdf link, html link]


Avira Antivir Arbritary Code Execution [LZH] - 28/05/2007
A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Buffer Overflow through Integer Cast Around in .LZH file parsing

This problem can lead to remote arbitrary code execution if an attacker carefully crafts a file that exploits the aforementioned vulnerability

Vulnerable Products
- Avira Antivir <7.03.00.09

dRead more [ txt link, pdf link, html link]



AVAST! Heap Overflow [CAB] - 24/05/2007
A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Heap Overflow through Integer Cast Around in .CAB file parsing

This problem can lead to remote arbitrary code execution if an attacker carefully crafts a file that exploits the aforementioned vulnerability

Vulnerable Products
- AVAST antivirus < 4.7.700

dRead more [ txt link, pdf link, html link]



AVAST! Heap Overflow [SIS] - 24/05/2007
A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Heap Overflow through Integer Cast Around in .SISfile parsing

This problem can lead to remote arbitrary code execution if an attacker carefully crafts a file that exploits the aforementioned vulnerability

Vulnerable Products
- AVAST antivirus < 4.7.700

dRead more [ txt link, pdf link]



ESET NOD32 Buffer Overflow [CAB] - 21/12/2006
A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Heap Overflow through Integer Overflow in .CAB file parsing

This problem can lead to remote arbitrary code execution if an attacker carefully crafts a file that exploits the aforementioned vulnerability

Vulnerable Products
- NOD32 < v.1.1743

dRead more [ html link]



ESET NOD32 Buffer Overflow [DOC] - 20/12/2006
A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Heap Overflow through Integer Overflow in .DOC File Parsing
- Divide by Zero in .CHM file parsing


This problem can lead to remote arbitrary code execution if an attacker carefully crafts a file that exploits the aforementioned vulnerability

Vulnerable Products
- NOD32 < v.1.1743

dRead more [ html link]


Bitdefender Packed PE File Heap Overflow - 15/12/2006
A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Heap Overflow through Integer Overflow in Packed PE File Parsing

Impact
This problem can lead to remote arbitrary code execution if an attacker carefully crafts a file that exploits the aforementioned vulnerability

Vulnerable Products
- BitDefender Antivirus,
- BitDefender Antivirus Plus,
- BitDefender Internet Security,
- BitDefender Mail Protection for Enterprises,
- BitDefender Online Scanner,
- BitDefender for ISA Server,
- BitDefender for MS Exchange 2000,
- BitDefender for MS Exchange 2003,
- BitDefender for MS Exchange 5.5

dRead more [ html link]



AVG Anti-Virus Multiple Remote Code Execution - 13/11/2006
A remotely exploitable vulnerabilityhas been found in the file parsing engine. In detail, the following flaw was determined:

- Heap Overflow through Integer Overflow in .CAB file parsing
- Uninitialized Variable flaw in .CAB file parsing.
- Divide by Zero in .DOC file parsing.
- Heap Overflow through Integer Overflow in .RAR file parsing
- Integer Issues in .EXE file parsing.

Impact
This problem can lead to remote arbitrary code execution if an attacker carefully crafts a file that exploits the aforementioned vulnerability

Vulnerable Products
- AVG Antivirus software versions prior to 7.1.407

dRead more [ html link]

Penetration Test