n.runs AG - Das Unternehmen Sicherheit
 
 
The Company
LEISTUNGSSPEKTRUM
IT INFRASTRUKTUR
IT SICHERHEIT SECURITY
IT BUSINESS CONSULTING
IT SOFTWARE

n.runs AG
Nassauer Straße 60
61440 Oberursel
Telefon: +49 (0) 6171/699-0
Telefax: +49 (0) 6171/699-199
E-mail: contact@nruns.com
Newsletter anfordern
Impressum

n.runs-SA-2008.002 F-Prot Out-of-Bound Memory Access DoS (remote) Advisory

n.runs AG
http://www.nruns.com
n.runs-SA-2008.002

security(at)nruns.com
16-Jul-2008

* * *


Vendor: FRISK (F-Prot), http://www.f-prot.com
Affected Product: F-Prot Anti-Virus all platforms < 4.4.4
Vulnerability: Out-of-Bound Memory Access DoS (remote)
Risk: HIGH

Vendor communication:

2008/01/22 initial notification to FRISK
2008/01/22 FRISK Response
2008/01/22 PGP public keys exchange
2008/01/23 n.runs has problems importing FRISK's provided public
key, so proceed to search on the key servers and import
the available ones and informs FRISK about it
2008/01/23 FRISK replies that the keys on the key server are fine to
be used.
2008/01/23 PoC files sent to FRISK
2008/01/26 FRISK acknowledges the PoC files and informs about having
some problem reproducing them and requests exact version
and configuration used to trigger the vulnerability
2008/01/28 FRISK communicates to n.runs that they were able to
reproduce one of the issues that they had just fixed
and that the update will be included in the upcoming
update
2008/01/28 n.runs thanks FRISK for such a quick response, provides
the exact version used while bug hunting and informs that
the issues were found about a year before; the reason of
the late report is because it was overseen until now.
2008/01/29 FRISK replies that the version used in the test is quite
old (4.3.1 against actual 4.4.3) and that during that
time many bugs had been fixed
2008/03/16 n.runs realizes that FRISK has released the update
because of a post on 27.Feb.2008 at the following link:
http://www.wilderssecurity.com/showpost.php?p=1191859&postcount=98
n.runs decides to not launch the advisory because
couldn't find an official post.
2008/07/10 n.runs finds the official announcement:
http://www.f-prot.com/download/ReleaseNotesWindows.txt
2008/07/16 n.runs releases this advisory


Overview:

FRISK Software International, established in 1993, is one of the world's leading companies in antivirus research and product development. FRISK Software produces the hugely popular F-Prot Antivirus product range offering unrivalled heuristic detection capabilities. In addition to this, the F-Prot AVES managed online e-mail security service filters away the nuisance of spam e-mail as well as viruses, worms and other malware that increasingly clog up inboxes and threaten data security. By supporting a wide range of platforms FRISK Software protects computer networks of all sizes, running on diverse platforms. As a result, FRISK Software provides its customers with comprehensive computer security solutions.


Description:

A remotely exploitable vulnerability has been found in the files' parsing engine. In detail, the following flaw was determined:

- DoS caused by an Out-of-Bound Memory Access while parsing CHM file's header: if the nb_dir field (Chunk number of root index chunk) value is set to 0xffffffff pointers math takes place and ends up in an out-of-bound read attempt.


Impact:

This problem can lead to remote denial of service if an attacker carefully crafts a file that exploits the aforementioned vulnerability. The vulnerability is present in FRISK Anti-virus software mentioned above, in all platforms supported by the affected products prior to the engine Version 4.4.4.


Solution:

The vulnerability was reported on 22.Jan.2008 and the engine 4.4.4 has been issued to solve this vulnerability. For detailed information about the fixes follow the link in References [1] section of this document. n.runs AG wants to highlight the excellent and fluent communication with FRISK and its very quick response to validate and fix the issue.


Credit:

Bugs found by Sergio Alvarez of n.runs AG.


Unaltered electronic reproduction of this advisory is permitted. For all other reproduction or publication, in printing or otherwise, contact security@nruns.com for permission. Use of the advisory constitutes acceptance for use in an "as is" condition. All warranties are excluded. In no event shall n.runs be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if n.runs has been advised of the possibility of such damages.

Copyright 2008 n.runs AG. All rights reserved. Terms of use apply.
Penetration Test
 

27 Oktober 2008:
Advisory: Eaton MGE OPS Network Shutdown Module authentication bypass and code execution

* * *

21 Oktober 2008:
Advisory: Internet Explorer HTML Object Memory Corruption

* * *

20 Oktober 2008:
Pressemitteilung
n.runs und Avira geben strategische Partnerschaft im IT-Sicherheitsumfeld bekannt

* * *

14 Oktober 2008:
Pressemitteilung
SYSTEMS 2008: n.runs AG präsentiert Bollwerk gegen den „Feind im eigenen Netz“ und Microsoft "Security Development Lifecycle Pro Network"

* * *

30 September 2008:
Corporate News
Zahlen des ersten Halbjahreszahlen 2008 bestätigen Expansionskurs
+++ Umsatzerlöse steigen um knapp 30 Prozent auf EUR 3,32 Millionen
+++ EBITDA um EUR 0,27 Millionen auf EUR -0,35 Millionen verbessert
+++ Ergebnis von Softwareinvestitionen geprägt, Consulting profitabel
+++ Ausblick 2008


* * *

17 September 2008:
Corporate News
n.runs wird durch Microsoft als Mitglied des neuen Programms Microsoft Security Development Lifecyle Pro Network berufen
+++ n.runs AG exklusives Mitglied im Microsoft SDL Pro Network
+++ Einziges Mitglied des MS SDL Pro Network auf europäischem Festland
+++ Mittelfristiger Umsatzbeitrag von über 10 Prozent geplant


* * *

17 September 2008:
Pressemitteilung
Software-Gigant beruft IT-Sicherheitsunternehmen zum Mitglied des "Microsoft Security Development Lifecycle Pro Network" Microsoft setzt im Rahmen ihres neuen Partnerprogramms "SDL Pro Network" in EMEA auf die n.runs AG

* * *

10 September 2008:
Advisory
Cross-Site Scripting Filter Evasion in various frameworks and applications

* * *

10 September 2008:
Advisory
Horde Framework Cross-Site Scripting in filename MIME attachments

* * *

25 August 2008:
Press-Release
IT-Sicherheit für Regierungen und Militär:
n.runs und Thales kooperieren


* * *

20 August 2008:
Artikel
"IT-Grundschutz" des BSI und secumedia Verlages - Antivirensoftware :
Wegbereiter für
Datendiebe


* * *

20 August 2008:
Press Release
Wachsende Bedrohung:
folgenschwere Angriffe auf E-Mail-/AV-Systeme nehmen stetig zu.


* * *

01 August 2008:
Advisory
MacOS X - CoreServices Framework's CarbonCore Framework Arbitrary Code Execution (remote)