|
|
| |
Credit:
The information has been provided by iDefense.
The original article can be found at:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=438
|
| |
Vulnerable Systems:
* Sophos Anti-Virus version 5.1 for Windows.
* Sophos Anti-Virus version 5 for Linux.
The problem manifests itself when the scanning engine encounters an executable compressed with petite that contains a large number of sections.
Successful exploitation would result in the scanning engine attempting to allocate an extremely large amount of memory resulting in memory exhaustion on the system in question. The auto-scan features of Sophos Anti-Virus will attempt to scan files on access.
Vendor Status:
Sophos recommends upgrading to an unaffected version of the scan engine.
CVE Information:
CVE-2006-4839
Vulnerable Systems:
* 09/15/2006 - Initial vendor notification
* 09/19/2006 - Initial vendor response
* 10/31/2006 - Coordinated public disclosure
|
|
|