Clamav crashes due to processing of standard filters in RAR VM, while processing a corrupted RAR file. Processing the corrupted file results in a null pointer deference .
Credit:
The information has been provided by Metaeye SG .
The original article can be found at: http://www.metaeye.org/advisories/54
Vulnerable Systems:
* Clam AntiVirus version 0.90 and prior
Immune Systems:
* Clam AntiVirus version 0.91
Impact:
Processing the corrupted file will result in crashing of clamscan application and clamd daemon.
Exploit:
The following corrupt RAR files can be used to test the vulnerability: http://www.metaeye.org/codes/corrupted.rar
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by