Deutsch | English
n.runs AG - Das Unternehmen Sicherheit
 
 
The Company
LEISTUNGSSPEKTRUM
IT INFRASTRUKTUR
IT SICHERHEIT SECURITY
IT BUSINESS CONSULTING
IT SOFTWARE

n.runs AG
Nassauer Straße 60
61440 Oberursel
Telefon: +49 (0) 6171/699-0
Telefax: +49 (0) 6171/699-199
E-mail: contact@nruns.com
Newsletter anfordern
Impressum

.NOD32 Antivirus CAB parsing Arbitrary Code Execution Advisory

n.runs AG
http://www.nruns.com
n.runs-SA-2006.005

security(at)nruns.com
21-Dec-2006

* * *

Vendor: ESET, http://eset.com
Affected Products: ESET NOD32 Antivirus
Vulnerability: Arbitrary Code Execution (remote)
Risk: HIGH

Vendor communication:
2006/08/24 initial notification of ESET
2006/08/28 ESET Response
2006/08/29 PGP keys exchange
2006/08/29 PoC files sent to ESET
2006/09/06 ESET initial feedback.
2006/09/08 ESET confirmed the bug and fixed
2006/09/08 ESET made available the updates

Overview:
Founded in 1992, ESET is a global provider of security software for enterprises and consumers. ESET’s award-winning, antivirus software system, NOD32, provides real-time protection from known and unknown viruses, spyware, rootkits and other malware. NOD32 offers the smallest, fastest and most advanced protection available, with more Virus Bulletin 100% Awards than any other antivirus product. ESET was named to Deloitte’s Technology Fast 500 five years running, and has an extensive partner network, including corporations like Canon, Dell and Microsoft. ESET has offices in Bratislava, SK; Bristol, U.K.; Buenos Aires, AR; Prague, CZ; San Diego, USA; and is represented worldwide in more than 100 countries. The broad product platform protects Windows, Linux, Novell and MS DOS machines.

Description:
A remotely exploitable vulnerability has been found in the file parsing engine.

In detail, the following flaw was determined:

  • Heap Overflow through Integer Overflow in .CAB file parsing

  • This problem can lead to remote arbitrary code execution if an attacker carefully crafts a file that exploits the aforementioned vulnerability. The vulnerability is present in NOD32 Antivirus software versions prior to the update v.1.1743.

    Solution:
    The vulnerability was reported on Aug 24 and an update has been issued on Sep 08 to solve this vulnerability through the regular update mechanism.

    Credit:
    Bugs found by Sergio Alvarez of n.runs AG.

    The information provided is released by n.runs "as is" without warranty of any kind. n.runs except all warranties, either express or implied, expect for the warranties of merchantability. In no event shall n.runs be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if n.runs has been advised of the possibility of such damages. Distribution or Reproduction of the information is provided that the advisory is not modified in any way.
    Copyright 2006 n.runs. All rights reserved. Terms of use.
    Penetration Test


    25 August 2008:
    Press-Release
    IT-Sicherheit für Regierungen und Militär:
    n.runs und Thales kooperieren

    * * *

    20 August 2008:
    Artikel
    "IT-grundschutz" des BSI und secumedia Verlages - Antivirensoftware :
    Wegbereiter für
    Datendiebe

    * * *

    20 August 2008:
    Press Release
    Wachsende Bedrohung:
    folgenschwere Angriffe auf E-Mail-/AV-Systeme nehmen stetig zu.

    * * *

    01 August 2008:
    Advisory: MacOS X - CoreServices Framework's CarbonCore Framework Arbitrary Code Execution (remote)

    * * *

    28 Juli 2008:
    Advisory: AVG Antivirus UPX parsing Divide by Zero

    * * *

    24 Juli 2008:
    PR-News
    Reaction to McAfee Statement regarding vulnerabilities in Anti-Virus Software

    * * *

    24 Juli 2008:
    Advisory: AVG Antivirus UPX parsing Divide by Zero

    * * *

    16 Juli 2008:
    Advisory: Quicktime - Arbitrary Code Execution

    * * *

    16 Juli 2008:
    Advisory: F-Prot Out-of-Bound Memory Access DoS (remote)

    * * *

    30 Juni 2008:
    Press-release
    Zentralisierung und Multi-Engine-Schutz vor Angriffen auf E-Mail-/AV-Systeme + n.runs schafft Sicherheit und Effizienz für Antivirensoftware

    * * *

    26 Juni 2008:
    Corporate News:
    Jahreszahlen 2007 und Ausblick 2008

    +++ Umsatzerlöse von EUR 5,48 Millionen
    +++ EBITDA von EUR -0,93 Millionen
    +++ Sonderbelastung durch Softwareentwicklung i.H.v. EUR 0,82 Millionen
    sowie Umstrukturierungs-maßnahmen
    +++ Auftragseingang im Mai 2008 + 47,6 Prozent auf EUR 6,2 Millionen
    +++ 2008 als bestes Jahr der Unternehmensgeschichte angestrebt

    * * *

    25 Juni 2008:
    Advisory :
    JSCAPE unsichere SSH Host key Validierung
    * * *

    24 Juni 2008:
    PR-News:
    +++ Virenscanner machen Angreifern den Weg ins Netzwerk frei +++
    * * *
    01 August 2008:
    Advisory: MacOS X - CoreServices Framework CarbonCore Framework Arbitrary Code Execution

    * * *

    01 Januar 1970:
    Advisory: AVG Antivirus UPX parsing Divide by Zero

    * * *

    16 Juli 2008:
    Advisory: QuicktimeArbitrary Code Execution

    * * *


    05 Mai 2008:
    Corporate News:
    +++ Kapitalerhöhung um weitere 75.000 Aktien beschlossen und platziert
    +++ Weiterentwicklung Application Protection System – Anti Virus (aps-AV)

    * * *

    29 April 2008:
    Corporate News:
    +++ Auftragseingang steigt im ersten Quartal um +34,6 Prozent +++ Neue Unternehmensstruktur n.runs professionals +++ Weitere Produkte im Bereich IT-Applications geplant
    * * *
    01 August 2008:
    Advisory: MacOS XCoreServices Framework CarbonCore FrameworkArbitrary Code Execution

    * * *

    01 Januar 1970:
    Advisory: AVG Antivirus UPX parsing Divide by Zero

    * * *

    16 Juli 2008:
    Advisory: QuicktimeArbitrary Code Execution

    * * *


    27 Februar 2008:
    Whitepaper :
    Hacking jBoss using a Browser