First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 109213
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
clamav-CVE-2005-3239.patch clamav-CVE-2005-3239.patch patch Thierry Carrez (RETIRED) 2005-10-26 02:47 0000 3.80 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 109213 depends on: Show dependency tree
Bug 109213 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-10-13 14:19 0000
Segfault with corrupted DOC files with ArchiveMaxFiles 10000. See Debian bug 
for full details.

------- Comment #1 From Sune Kloppenborg Jeppesen 2005-10-13 22:41:04 0000 -------
antivirus/net-mail please advise. 

------- Comment #2 From Thierry Carrez (RETIRED) 2005-10-14 01:15:45 0000 -------
Nothing yet upstream afaict

------- Comment #3 From Thierry Carrez (RETIRED) 2005-10-15 01:35:32 0000 -------
This is CAN-2005-3239

------- Comment #4 From Sune Kloppenborg Jeppesen 2005-10-19 10:54:07 0000 -------
Still nothing upstream. 

------- Comment #5 From Thierry Carrez (RETIRED) 2005-10-26 02:47:30 0000 -------
Created an attachment (id=71477) [details]
clamav-CVE-2005-3239.patch

Patch extracted from clamav CVS, untested.

------- Comment #6 From Thierry Carrez (RETIRED) 2005-10-26 02:48:05 0000 -------
antivirus / net-mail: please check/apply patch and bump.

------- Comment #7 From Andrej Kacian (RETIRED) 2005-10-28 04:12:32 0000 -------
I'm sorry, I'll be out of touch until Monday, so I can't do this one on time.
BTW, is there a sample corrupted .doc file to test on? I couldn't find any.

------- Comment #8 From Thierry Carrez (RETIRED) 2005-10-28 04:20:00 0000 -------
There is one on the Debian bug :
http://bugs.debian.org/cgi-bin/bugreport.cgi/KOCH.DOC?bug=333566;msg=19;att=1

------- Comment #9 From Andrej Kacian (RETIRED) 2005-11-03 15:25:50 0000 -------
There is 0.87.1 out which fixes this. Ebuild is now in portage, x86 already
tested and stable.

------- Comment #10 From Sune Kloppenborg Jeppesen 2005-11-03 23:41:15 0000 -------
Arches please test and mark stable. 

------- Comment #11 From Thierry Carrez (RETIRED) 2005-11-04 00:52:38 0000 -------
Potential additional security fixorz :
- libclamav/petite.c: fix boundary checks (acab)
- libclamav/mbox.c: scan attachments that have no filename (njh)
- libclamav/fsg.c: fix buffer size calculation in unfsg_133
  Reported by Zero Day Initiative (ZDI-CAN-004)
- libclamav/tnef.c: fix possible infinite loop
  Reported by iDEFENSE (IDEF1169).
- libclamav/mspack/cabd.c: fix possible infinite loop in cabd_find (tk)
  Reported by iDEFENSE (IDEF1180).

------- Comment #12 From Gustavo Zacarias (RETIRED) 2005-11-04 05:37:22 0000 -------
sparc stable.

------- Comment #13 From Brent Baude 2005-11-04 06:46:06 0000 -------
marked ppc64 stable

------- Comment #14 From Jose Luis Rivero (yoswink) 2005-11-05 03:10:30 0000 -------
0.87.1 stable on alpha

------- Comment #15 From Thierry Carrez (RETIRED) 2005-11-05 04:42:46 0000 -------
The fsg thing allows remote code execution :

))))))))))))))))
ZDI-05-002: Clam Antivirus Remote Code Execution Vulnerability
http://www.zerodayinitiative.com/advisories/ZDI-05-002.html
CAN-2005-3303

This vulnerability allows remote attackers to execute arbitrary code on
vulnerable ClamAV installations. Authentication is not required to
exploit this vulnerability.

This specific flaw exists within libclamav/fsg.c during the unpacking of
executable files compressed with FSG v1.33. Due to invalid bounds
checking when copying user-supplied data to heap allocated memory, an
exploitable memory corruption condition is created. The unpacking
algorithm for other versions of FSG is not affected. 
)))))))))))))))))

------- Comment #16 From Michael Hanselmann (hansmi) (RETIRED) 2005-11-06 02:58:52 0000 -------
Stable on ppc and hppa.

------- Comment #17 From Simon Stelling (RETIRED) 2005-11-06 03:07:04 0000 -------
amd64 happy too

------- Comment #18 From Sune Kloppenborg Jeppesen 2005-11-06 08:18:20 0000 -------
GLSA 200511-04  
 
ia64 don't forget to mark stable. 

First Last Prev Next    No search results available      Search page      Enter new bug