Search This Blog

Monday, October 10, 2005

[NT] HAURI Anti-Virus ALZ Archive Handling Buffer Overflow

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html

- - - - - - - - -

HAURI Anti-Virus ALZ Archive Handling Buffer Overflow
------------------------------------------------------------------------

SUMMARY

<http://www.hauri.net/> HAURI offers "virus detection software (ViRobot)
for servers (Windows/Unix), mail gateways (Domino/Exchange) and desktop
(Windows) environments".

Secunia Research has discovered a vulnerability in various HAURI
anti-virus products, which can be exploited by malicious people to
compromise a vulnerable system.

DETAILS

Vulnerable Systems:
* ViRobot Expert 4.0
* ViRobot Advanced Server
* HAURI LiveCall

With vrAZMain.dll version 5.8.22.137

Immune Systems:
* vrAZMain.dll version 5.9.22.154

The vulnerability is caused due to a boundary error in the archive
decompression library when reading the filename of a compressed file from
an ALZ archive. This can be exploited to cause a stack-based buffer
overflow when a malicious ALZ archive is scanned.

Successful exploitation allows arbitrary code execution, but requires that
compressed file scanning is enabled.

Solution:

Apply updates.

ViRobot Expert 4.0 / ViRobot Advanced Server:
Update to the latest version via online update. (vrAZMain.dll version
5.9.22.154)

HAURI LiveCall:
Update to the latest version by visiting the vendor's LiveCall website.
(vrAZMain.dll version 5.9.22.154)

ADDITIONAL INFORMATION

The information has been provided by <mailto:vuln@secunia.com> Secunia
Research.
The original article can be found at:
<http://secunia.com/secunia_research/2005-47/advisory/>
http://secunia.com/secunia_research/2005-47/advisory/

========================================

This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.

No comments: