CERT-In Vulnerability Note
CIVN-2005-0119
Symantec AntiVirus RAR Archive Decompression Buffer Overflow
Original Issue Date:December 26, 2005
Severity Rating: HIGH
Systems Affected
- Symantec AntiSpam for SMTP
- Symantec AntiVirus Corporate Edition 10.x
- Symantec AntiVirus for Caching 4.x
- Symantec AntiVirus for Clearswift 4.x
- Symantec AntiVirus for Handhelds 3.x
- Symantec AntiVirus for Microsoft ISA Server 4.x
- Symantec AntiVirus for Microsoft SharePoint 4.x
- Symantec AntiVirus for Network Attached Storage 4.x
- Symantec AntiVirus for SMTP Gateways 3.x
- Symantec AntiVirus Scan Engine 4.x
- Symantec AntiVirus/Filtering for Domino 3.x
- Symantec Brightmail AntiSpam 4.x, AntiSpam 5.x, AntiSpam 6.x
- Symantec Client Security 3.x
- Symantec Client Security for Nokia Communicator
- Symantec Mail Security for Domino 4.x, Microsoft Exchange 5., Exchange 4.x
- Symantec Norton AntiVirus 2004, 2005, 2006
- Symantec Norton AntiVirus for Macintosh 9.x
- Symantec Norton AntiVirus for Microsoft Exchange 2.x
- Symantec Norton AntiVirus Solution 7.5
- Symantec Norton Internet Security 2004 Professional, 2005, 2006
- Symantec Norton Internet Security for Macintosh 3.x
- Symantec Norton Personal Firewall 2004, 2005, 2006
- Symantec Norton SystemWorks 2004, 2005, 2006
- Symantec Norton SystemWorks for Macintosh 3.x
- Symantec Scan Engine 5.x
- Symantec Web Security 3.x
Overview
Multiple heap buffer overflows vulnerabilities have been reported in Symantec RAR decompression library Dec2RAR.dll, which could allow remote attackers to execute arbitrary code or cause denial of service.
Description
Symantec RAR decompression library Dec2RAR.dll is used to parse different file formats to detect malware. This vulnerability is caused due to a boundary error in Dec2Rar.ll while copying data based on the 16bit length fields in the sub-block headers of a RAR archive. An attacker could exploit these vulnerabilities by causing a Symantec Anti virus product to scan a malicious RAR archive via hosting a malicious web site, as an email attachment, or network share.
An attacker who successfully exploits this vulnerability could execute arbitrary code or cause denial of service.
Workaround
Disable scanning of RAR compressed files For further details refer Symantec AntiVirus Decomposition Buffer Overflow SYM05-027
Vendor Information
Symantec
http://securityresponse.symantec.com/avcenter/security/Content/2005.12.21b.html
References
Secunia Advisory
http://secunia.com/advisories/18131/
US-CERT
http://www.kb.cert.org/vuls/id/305272
xForce
http://xforce.iss.net/xforce/alerts/id/187
Security focus BID 15971
http://www.securityfocus.com/bid/15971/info
http://www.rem0te.com/public/images/symc2.pdf
CVE Name
CAN-2005-4438
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|