TUCoPS :: Security App Flaws :: va1152.htm

clamav: Crash with crafted chm, CVE-2008-1389
clamav: Crash with crafted chm, CVE-2008-1389
clamav: Crash with crafted chm, CVE-2008-1389



--nextPart1700928.7gSh03MQtM
Content-Type: text/plain;
  charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

clamav: Crash with crafted chm, CVE-2008-1389

References

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1389 
http://int21.de/cve/CVE-2008-1389-clamav-chd.html 
http://www.int21.de/cve/cve-2008-1389-samples.tar.bz2 
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1089

Description

A fuzzing test showed weakness in the chm parser of clamav, which can possibly 
be exploited.
The clamav team has disabled the chm module in older versions though freshclam 
updates and has released 0.94 with a fixed parser.

The clamav team has not mentioned this issue in the release notes of 0.94, 
which is very bad security behaviour.

Disclosure Timeline

2008-07-09: clamav bug opened
unknown date: clamav disables chm-parser through freshclam
2008-09-02 Vendor releases 0.94
2008-09-04 Released this advisory

CVE Information

The Common Vulnerabilities and Exposures (CVE) project has assigned the name 
CVE-2008-1389 to this issue. This is a candidate for inclusion in the CVE 
list (http://cve.mitre.org/), which standardizes names for security problems. 

Credits and copyright

This vulnerability was discovered by Hanno Boeck of schokokeks.org webhosting. 
It's licensed under the creative commons attribution license.

Hanno Boeck, 2008-09-04, http://www.hboeck.de 

=2D- 
Hanno B=C3=B6ck		Blog:		http://www.hboeck.de/ 
GPG: 3DBD3B20		Jabber/Mail:	hanno@hboeck.de 

--nextPart1700928.7gSh03MQtM
Content-Type: application/pgp-signature; name=signature.asc 
Content-Description: This is a digitally signed message part.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.9 (GNU/Linux)

iEYEABECAAYFAki/6q4ACgkQr2QksT29OyCw2ACeLAZj8BiD2+yRkJSs+X9PMyLl
8+AAnicUkoBy3+y2ChE9Cje4t6lO7lFJ
=Y8AO
-----END PGP SIGNATURE-----

--nextPart1700928.7gSh03MQtM--

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH