SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Sophos Anti-Virus 6.5.4 Vulnerability


Arrow  SecurityAlert : 3107
Arrow  CVE : CVE-2007-4512
Arrow  SecurityRisk : Low  Security Risk Low  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Exploit Available : No
Arrow  Credit : contextis
Arrow  Published : 11.09.2007

Arrow  Affected Software : Sophos Anti-Virus, version 6.5.4 R2



Arrow  Advisory Content :  

Name Cross Site Scripting Vulnerability in Sophos Anti-Virus

Systems Affected Sophos Anti-Virus, version 6.5.4 R2
Severity Medium
Category Cross Site Scripting
Author Context Information Security Ltd
Advisory 6th September 2007

Description
-----------
A ZIP archive containing a virus signature with a malformed file name will
cause a Cross Site Scripting vulnerability to be triggered from within the
Sophos Anti Virus client.

Analysis
--------
When Sophos anti-virus scans a specially crafted ZIP archive containing a
XSS attack string, it will internally log the string. When this
information is accessed via the Sophos client (SavMain.exe) the XSS attack
string is unencoded. When the print function is called, the application
can be used to run arbitrary code on the target machine from an external
attacker?s submitted file.

Technologies Affected
---------------------
Sophos Anti-Virus, version 6.5.4 R2

Resolution
----------
Update to version 6.5.8 or 7.0.

Vendor Response
---------------
Sophos have patched this issue in version 7.01.

CVE Details
-----------
This issue has been provisionally assigned a CVE candidate number of
CVE-2007-4512

Disclosure Timeline
-------------------
18 April 2007 ? Initial Discovery and vendor notification
19 April 2007 ? Vendor Response
21 August 2007 ? Second Vendor Response
6 September 2007 - Coordinated Public Release

Credits
--------
Michael Jordon of Context Information Security Ltd

About Context Information Security
----------------------------------

Context Information Security Limited is a specialist information security
consultancy based in London and Frankfurt. Context promotes the holistic
approach to information security and helps clients to identify, assess and
control their exposure to risk within the fields of IT, telephony and
physical security. Context employs experienced information security
professionals who are subject-matter experts in their various technical
specialisms. Context works extensively within the finance, legal, defence
and government sectors, delivering high-end information security projects
to organisations for which security is a priority.

Web: www.contextis.co.uk
Email: disclosure (at) contextis.co (dot) uk [email concealed]

About Sophos
------------

"Sophos is a world leader in IT security and control solutions
purpose-built for business, education, government organizations and service
providers. Our reliably engineered, easy-to-operate products protect over
100 million users in more than 150 countries from viruses, spyware, adware,
Trojans, intrusion, spam, policy abuse, and uncontrolled network access."






Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1
   session.save_path
   safe_mode and
   open_basedir bypass

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

Copyright © SecurityReason.com. All Rights Reserved.