Press CTRL-D to bookmark us
Welcome Guest Login / Register / Members
Search in  
Top Submit newsSubscribe
Communication | Computer Crime | Digital Audio, Video, Photo | General News | Hardware | Internet | Mobile | PDA | Security | Software | Vulnerability |


Previous articleBack to news listNext article
 

 Sponsored links

Want to become one of our authors and see your work published on ALLSeek.iNFO ?
 
 Clam AntiVirus 'clamav-milter' Format String Flaw Lets Remote Users Execute Arbitrary Code
Categorie: Vulnerability
Posted: 2003-11-13 by ReCall
Views: 355
Source: Click here
 
Current Rating: Not rated
Poor Best
 Details
Description: A format string vulnerability was reported in Clam AntiVirus. A remote user can execute arbitrary code on the target system.

Secure Network Operations Strategic Reconnaissance Team reported that clamav-milter contains a format string flaw that can be exploited by a remote user if syslog support is configured.

A remote user can send an e-mail with a specially crafted "From:" address containing "%" characters and with e-mail content that will trigger a virus rule to the target system. In this case, the remote user's e-mail address will be passed to syslog() without appropriate validation. The syslog call is reportedly made without a format specifier. A remote user can cause the target Clam AntiVirus software to crash or to execute arbitrary code.

A demonstration exploit string is provided:

"mail from: %n%n%n%n%n%n%n"

Impact: A remote user can cause the 'clamav-milter' process to crash or execute arbitrary code. The arbitrary code will run with the privileges of the Clam AntiVirus user or with root privileges, depending on how the system is configured.

Solution: The vendor has released a fix in clamav-devel-20031111 and clamav-0.65, available at:

http://cvs.sourceforge.net/viewcvs.py/clamav/clamav-devel/
http://prdownloads.sou rceforge.net/clamav/

The author of the report indicates that you can, as a workaround, disable syslog support.
 
Syndication
Permalink Email this

The URI to TrackBack this entry is:
http://allseek.info/news/trackback.php?id=535

User comments (post your comments here)

Only registerd members can post comments and articles
 

Previous articleBack to news listNext article
 



InterJOB.su

SpyLOG Page Rank Checker
LAST QUERIES