n.runs AG - Das Unternehmen Sicherheit
 
 
The Company
LEISTUNGSSPEKTRUM
IT INFRASTRUKTUR
IT SICHERHEIT SECURITY
IT BUSINESS CONSULTING
IT SOFTWARE

n.runs AG
Nassauer Straße 60
61440 Oberursel

Telefon: +49 (0) 6171/699-0
Telefax: +49 (0) 6171/699-199
E-mail: contact@nruns.com
Impressum

n.runs-SA-2007.025 ClamAV Remote Code Execution Advisory

n.runs AG
http://www.nruns.com
n.runs-SA-2007.025

security(at)nruns.com
24-Aug-2007

* * *


Vendor: ClamAV, http://www.clamav.net
Affected Products:
- ClamAV, http://www.clamav.net


Vulnerability: Remote Code Execution
Risk: MEDIUM

Vendor communication:

20070810 Initial notification to ClamAV
20070810 ClamAV Responses
20070810 PoC files sent to ClamAV
20070821 ClamAV releases version 0.91.2
20070822 n.runs AG releases a coordinated disclosure advisory


Overview:

Clam AntiVirus is an open source (GPL) anti-virus toolkit for UNIX, designed especially for e-mail scanning on mail gateways. It provides a number of utilities including a flexible and scalable multi-threaded daemon, a command line scanner and advanced tool for automatic database updates. The core of the package is an anti-virus engine available in a form of shared library.


Description:

A remotely exploitable vulnerability has been found in clamav-milter when used with sendmail. In detail, the following flaw was determined:

- Arbitrary code execution due to insecure call to popen()


Impact:

This vulnerability can lead to remote code execution with root privileges. Leading to a complete compromise of the vulnerable system. An attacker can inject shell commands into the recipient field of sendmail, if clamav-milter was started with the black hole mode activated. The vulnerability is present in at least clamav version 0.91.1, prior versions may also be affected.


Solution:

A new stable release (clamav 0.91.2) is available at the clamav website which fixes the vulnerability.


Credit:

Bugs found by Nikolaos Rangos of n.runs AG.


Unaltered electronic reproduction of this advisory is permitted. For all other reproduction or publication, in printing or otherwise, contact security@nruns.com for permission. Use of the advisory constitutes acceptance for use in an "as is" condition. All warranties are excluded. In no event shall n.runs be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if n.runs has been advised of the possibility of such damages.

Copyright 2007 n.runs AG. All rights reserved. Terms of use apply.
Penetration Test



05 Mai 2008:
Corporate News:
+++ Kapitalerhöhung um weitere 75.000 Aktien beschlossen und platziert
+++ Weiterentwicklung Application Protection System – Anti Virus (aps-AV)

* * *
29 April 2008:
Corporate News:
+++ Auftragseingang steigt im ersten Quartal um +34,6 Prozent +++ Neue Unternehmensstruktur n.runs professionals +++ Weitere Produkte im Bereich IT-Applications geplant

* * *
27 Februar 2008:
Whitepaper :
Hacking jBoss using a Browser

* * *

19 Februar 2008:
        cebit
n.runs AG auf der CeBIT :
Halle 6, Stand J61/1
aps-AV zur Absicherung "offener" AntiViren-Strukturen

* * *
24 Januar 2008 :
Corporate News:
n.runs AG erschließt mit eigener Lösungsentwicklung weiteres Geschäftsfeld IT-Applications +++ aps-AV als erste Hochsicherheitslösung gelauncht

* * *

19 Dezember 2007:
Corporate News: Kapitalerhöhung beschlossen und platziert
+++ Bruttoemissionserlös dient der Finanzierung der Softwareeinführung


* * *

3 Dezember 2007:

Presse : Virenscanner öffnen Hacker die Türen

* * *
13 November 2007:
Conference / Talk : The Death of AV Defense in Depth ? - Revisiting Anti-Virus Software (Hack.lu 2007)

* * *

03 September 2007:
Advisory: Sophos Antivirus UPX parsing Code execution UPDATE

* * *

24 August 2007:
Advisory: ClamAV Remote Code Execution

* * *

24 August 2007:
Advisory: Sophos Antivirus Arbitrary Code Execution [UPX]

* * *

24 August 2007:
Advisory: Sophos Antivirus Infinite Loop DoS [BZIP]

* * *

25 Juli 2007:
Advisory: CA eTrust Antivirus Infinite Loop DoS [CHM]

* * *