T L Anews.com

Information for Security Concerned People

TLAnews
Search
 
 

TLAflash Registration
 
Tech Doc
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Linux Antivirus Software Found Vulnerable To Bzip2 Bombs

19.01.2004

 

Antivirus products from several vendors could be vulnerable to exploitation by attackers, a German security firm said this week.

AERAsec Network Services and Security, based in Hohenbrunn, Germany, discovered a flaw in at least three Linux antivirus products that could allow a hacker to conduct a denial-of-service (DoS) attack on a system running Kaspersky AntiVirus for Linux 5.0.1.0, Trend Micro InterScan VirusWall 3.8 Build 1130, and McAfee Virus Scan for Linux 4.16.0. Other versions from these vendors, as well as antivirus packages from other companies, may also be at risk, according to AERAsec.

The problem stems from how some antivirus programs handle compressed .zip files. Typically, antivirus software decompresses .zip archives prior to sniffing their contents for malicious code. If a hacker crafted an especially large .zip file -- dubbed a "bzip2 bomb" -- these products can choke on the processing, eating up all the available file space and maxing out the CPU. The result: a DoS.

Fixes for the vulnerabilities are not yet available from the vendors cited.

 

Related information


 

Author information.
Copyright © [Telecom and Logistics Associates Sàrl]. All rights reserved.
Revised: janvier 18, 2004 .

All information provided is of a general nature and is not intended to address the circumstances of any particular individual or entity. Although we endeavor to provide accurate and timely information, there can be no guarantee that such information is accurate as of the date it is received or that it will continue to be accurate in the future. No one should act upon such information without appropriate professional advice after a thorough examination of the facts of the particular situation.

   
 
 
 
 
 
 
 
 Publications
  
 Christian ALT  
      
   
Translate this page from:
 
 
Résumé en français