SecurityAlert : 535 CVE : CVE-2006-1091 SecurityRisk : Medium (About) Remote Exploit : Yes Local Exploit : No Exploit Given : Yes Credit : Michael Lang jackal-net at Published : 05.03.2006
Affected Software :
Kaspersky AV Scanner x<= 5.5.3
Advisory Text :
Hi,
i've recently discovered a design problem in Kaspersky AV Scanner. Original
seen on FileScanner for Unix 5.0.5 the Problematic files are also screewing
up the latest 5.5.3 Version.
AS i didnt find an offical way to deploy this at Kaspersky i hope someone
from them will read this
and contact me to get a POC.
Therefore not all details will be shown here to avoid massive attacks.
The file(s) are 1.6M of size and dont contain suspicous content.
calling 3 kavscanner instances already renders a P4 2.4Ghz Machine with
512Mb Ram useless after a few seconds.
A POC flashcapture is located at
http://www.jackal-net.at/KasperskyLeakPOC.swf
did anyone else encountered a similar problem ?
ClamAV works fine on the same Files.
Kind Regards
Michael Lang
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Maksymilian Arciemowicz discovered a Integer Overflow
vulnerability in the libc library "strfmon()" function.A vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected *BSD systems.