FrSIRT Advisory : FrSIRT/ADV-2005-1934
CVE Reference : GENERIC-MAP-NOMATCH
Rated as : Critical
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2005-10-03
* Technical Description *
A vulnerability has been identified in various Kaspersky Anti-Virus products, which could be exploited by attackers or malware to execute arbitrary commands. This flaw is due to a heap overflow error in the CAB file format parser (cab.ppl) that does not properly handle a specially crafted file containing a malformed header, which could be exploited by attackers to execute arbitrary commands and compromise a vulnerable system (e.g. by sending an email containing a malicious CAB file).
The issue has been reported in version 5.0.20.0 of the CAB scanning library (cab.ppl). Other versions may also be vulnerable.
* Affected Products *
Kaspersky Anti-Virus 4.x
Kaspersky Anti-Virus 5.x
Kaspersky SMTP-Gateway 5.x
* Solution *
The FrSIRT is not aware of any official supplied patch for this issue.
* References *
http://www.frsirt.com/english/advisories/2005/1934
http://www.rem0te.com/public/images/kaspersky.pdf

ino
05-10-04 15:20
0개
2,629회
Kaspersky Anti-Virus Products Remote Heap Overflow Vulnerability
댓글목록
등록된 댓글이 없습니다.