CERT-In Vulnerability Note
CIVN-2004-0061
Detection Evasion vulnerability in multiple Anti Virus Products
Original Issue Date:October 21, 2004
Severity Rating: HIGH
Systems Affected
Multiple Anti Virus Products including McAfee, Computer Associates, Kaspersky, Sophos, Eset and RAV
Overview
Anti Virus products of multiple vendors including McAfee,Computer Associates, Kaspersky, Sophos, Eset and RAV have exceptional condition error. Security protection of the antivirus products can be bypassed by exploitation of the error condition by malicious users remotely.
Impact
- DoS
- System Compromise
- Data Corruption.
Description
The vulnerability exists specifically in the parsing of .zip archive headers. In . zip Archives information about compressed files is stored in two headers one local and the other global. The local header exists just before the compressed data of each file, and the global header exists at the end of the .zip archive. It is possible to modify the uncompressed size of archived files in both the local and global header without affecting functionality. The exceptional condition error when successfully exploited will allow remote malicious users to pass malicious payloads to a remote user in a compressed archive file without being detected.
The problem is more profound as it is generally assumed that Anti Virus products have the ability to scan compressed archives, the successful malicious payload can very easily infect the victim.
Workaround
Filter all compressed file archives .zip at the gateway levels, regardless of content.
Solution
A few vendors have released updates in their anti-virus products.
Vendor Information
McAfee
www.mcafee.com
Computer Associates
http://supportconnectw.ca.com/
Kaspersky
www.kaspersky.com/
Sophos
www.sophos.com
Eset
www.nod32.com
RAV
www.ravantivirus.com/
References
Idefense
http://www.idefense.com/application/poi/display?id=153&type=vulnerabilities
Computer Associates
http://supportconnectw.ca.com/public/ca_common_docs/arclib_vuln.asp
CVE Name
CAN-2004-0932
CAN-2004-0933
CAN-2004-0934
CAN-2004-0935
CAN-2004-0936
CAN-2004-0937
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|