Short Name |
HTTP:STC:DL:CLAMAV-JPEG-DOS
|
Severity |
High
|
Recommended |
No
|
Recommended Action |
Drop
|
Category |
HTTP
|
Keywords |
ClamAV AntiVirus cli_check_jpeg_exploit Function Denial of Service
|
Release Date |
2010/10/19
|
Update Number |
1794
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+
|
HTTP: ClamAV AntiVirus cli_check_jpeg_exploit Function Denial of Service
This signature detects attempts to exploit a known buffer overflow vulnerability in the ClamAV AntiVirus product. It can be triggered when the application processes crafted JPEG files. An unauthenticated attacker can exploit this by delivering a crafted file to the scanning service resulting in an unchecked recursion which consumes the stack and causes a denial-of-service condition. In a successful attack, the affected ClamAV daemon terminates. This can allow for further exploitation of the target system, exposing the system to other threats in absence of the AntiVirus daemon.
Extended Description
ClamAV is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to cause denial-of-service conditions. Given the nature of this issue, attackers may also be able to run arbitrary code, but this has not been confirmed.
Versions prior to ClamAV 0.94.2 are vulnerable.
Affected Products
- Apple Mac OS X Server 10.4.11
- Apple Mac OS X Server 10.5.6
- Clam Anti-Virus ClamAV 0.93
- Clam Anti-Virus ClamAV 0.93.1
- Clam Anti-Virus ClamAV 0.94
- Clam Anti-Virus ClamAV 0.94.1
- Debian Linux 4.0
- Debian Linux 4.0 Alpha
- Debian Linux 4.0 Amd64
- Debian Linux 4.0 Arm
- Debian Linux 4.0 Hppa
- Debian Linux 4.0 Ia-32
- Debian Linux 4.0 Ia-64
- Debian Linux 4.0 M68k
- Debian Linux 4.0 Mips
- Debian Linux 4.0 Mipsel
- Debian Linux 4.0 Powerpc
- Debian Linux 4.0 S/390
- Debian Linux 4.0 Sparc
- Gentoo Linux
- Kolab Kolab Groupware Server 2.0.1
- Kolab Kolab Groupware Server 2.0.2
- Kolab Kolab Groupware Server 2.0.3
- Kolab Kolab Groupware Server 2.0.4
- Kolab Kolab Groupware Server 2.1.0
- Kolab Kolab Groupware Server 2.2.0
- Mandriva Corporate Server 3.0.0
- Mandriva Corporate Server 3.0.0 X86 64
- Mandriva Corporate Server 4.0
- Mandriva Corporate Server 4.0.0 X86 64
- Mandriva Linux Mandrake 2008.0
- Mandriva Linux Mandrake 2008.0 X86 64
- Mandriva Linux Mandrake 2008.1
- Mandriva Linux Mandrake 2008.1 X86 64
- Mandriva Linux Mandrake 2009.0
- Mandriva Linux Mandrake 2009.0 X86 64
- SuSE Linux 10.3
- SuSE Linux 11
- SuSE SUSE Linux Enterprise Server 10
- SuSE SUSE Linux Enterprise Server 9
- Ubuntu Ubuntu Linux 8.10 Amd64
- Ubuntu Ubuntu Linux 8.10 I386
- Ubuntu Ubuntu Linux 8.10 Lpia
- Ubuntu Ubuntu Linux 8.10 Powerpc
- Ubuntu Ubuntu Linux 8.10 Sparc
References