security

Total 112
Today 0
profile_image
ino
05-10-04 15:20 0개 2,629회
Kaspersky Anti-Virus Products Remote Heap Overflow Vulnerability
FrSIRT Advisory : FrSIRT/ADV-2005-1934

CVE Reference : GENERIC-MAP-NOMATCH

Rated as : Critical

Remotely Exploitable : Yes

Locally Exploitable : Yes

Release Date : 2005-10-03



* Technical Description *



A vulnerability has been identified in various Kaspersky Anti-Virus products, which could be exploited by attackers or malware to execute arbitrary commands. This flaw is due to a heap overflow error in the CAB file format parser (cab.ppl) that does not properly handle a specially crafted file containing a malformed header, which could be exploited by attackers to execute arbitrary commands and compromise a vulnerable system (e.g. by sending an email containing a malicious CAB file).



The issue has been reported in version 5.0.20.0 of the CAB scanning library (cab.ppl). Other versions may also be vulnerable.



* Affected Products *



Kaspersky Anti-Virus 4.x

Kaspersky Anti-Virus 5.x

Kaspersky SMTP-Gateway 5.x



* Solution *



The FrSIRT is not aware of any official supplied patch for this issue.



* References *



http://www.frsirt.com/english/advisories/2005/1934

http://www.rem0te.com/public/images/kaspersky.pdf

댓글목록

등록된 댓글이 없습니다.