Security Advisories

FSC-2008-3: RPM PARSING VULNERABILITY

Description

If attackers send specially-made compressed file archives to users, whose antivirus software is set to scan inside compressed archives, this causes an integer overflow. The result is a controlled buffer overflow attack. It allows the attackers to control the computer on the system level.
 

Affected Products


Clients

Risk Level: HIGH
(Low/Medium/High/Critical)
  • F-Secure Internet Security 2009
  • F-Secure Internet Security 2008
  • F-Secure Internet Security 2007 Second Edition
  • F-Secure Internet Security 2007
  • F-Secure Internet Security 2006
  • F-Secure Anti-Virus 2009
  • F-Secure Anti-Virus 2008
  • F-Secure Anti-Virus 2007 Second Edition
  • F-Secure Anti-Virus 2007
  • F-Secure Anti-Virus 2006
  • F-Secure Client Security 7.12 and earlier
  • F-Secure Anti-Virus for Workstations 7.11 and earlier
  • F-Secure Linux Security 7.01 and earlier
  • F-Secure Anti-Virus Linux Client Security 5.54 and earlier
  • Solutions based on F-Secure Protection Service for Consumers version 8.00 and earlier
  • Solutions based on F-Secure Protection Service for Business version 3.10 and earlier
 
Servers

Risk Level: CRITICAL
(Low/Medium/High/Critical)
  • F-Secure Home Server Security 2009
  • F-Secure Anti-Virus for Windows Servers 8.00 and earlier
  • F-Secure Anti-Virus for Citrix Servers 7.00 and earlier
  • F-Secure Linux Security 7.01 and earlier
  • F-Secure Anti-Virus Linux Server Security 5.54 and earlier
 
Gateways

Risk Level: CRITICAL
(Low/Medium/High/Critical)
  • F-Secure Anti-Virus for Microsoft Exchange 7.10 and earlier
  • F-Secure Internet Gatekeeper for Windows 6.61 and earlier
  • F-Secure Internet Gatekeeper for Linux 2.16 and earlier
  • F-Secure Anti-Virus for MIMEsweeper 5.61 and earlier
  • F-Secure Messaging Security Gateway 5.0.4 and earlier

 

Platforms

All platforms supported by the affected products.

 

Mitigating Factors

Attackers can exploit the vulnerability only if the antivirus software is set to scan inside compressed archives. In general, compressed archives are scanned during scheduled scans on servers and in gateway environments. In a typical configuration, on-access scanning does not scan inside compressed archives. Therefore, attackers cannot usually exploit the vulnerability in client environments.

Attackers can exploit the vulnerability by sending specially-made compressed file archives to users. At the time of publishing the Security Bulletin, there are no known exploits.

 

Patch Available

Product Versions Download
F-Secure Client Security 7.12,
7.11
ftp://ftp.f- secure.com/support/hotfix/fsavcs/fsav744-03-signed.fsfix
F-Secure Anti-Virus for Workstations 7.11
7.10
ftp://ftp.f- secure.com/support/hotfix/fsav/fsav744-03-signed.fsfix
F-Secure Anti-Virus for Windows Servers 8.00 ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsav830-01-signed.fsfix
F-Secure Anti-Virus for Windows Servers 7.01,
7.00
ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsav722-02-signed.fsfix
F-Secure Anti-Virus for Citrix Servers 7.00 ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsav722-02-signed.fsfix
F-Secure Anti-Virus for Citrix Servers 5.52 ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsavsr552-16- signed.fsfix
F-Secure Linux Security 7.01 http://www.f- secure.com/webclub/fsls.html
F-Secure Linux Client Security 5.54 http://www.f- secure.com/webclub/fsls5.html
F-Secure Linux Server Security 5.54 http://www.f- secure.com/webclub/fsssl.html
F-Secure Anti-Virus for Microsoft Exchange 7.10 ftp://ftp.f-secure.com/support/hotfix/fsav-mse/fsavmse710-04.zip
F-Secure Anti-Virus for Microsoft Exchange 7.00 ftp://ftp.f-secure.com/support/hotfix/fsav-mse/fsavmse700-03.zip
F-Secure Anti-Virus for Microsoft Exchange 6.62 ftp://ftp.f-secure.com/support/hotfix/fsav-mse/fsavmse662-07.zip
F-Secure Internet Gatekeeper for Windows 6.61 ftp://ftp.f-secure.com/support/hotfix/fsig/fsigk661-03.zip
F-Secure Internet Gatekeeper for Linux 2.16 http://www.f-secure.com/webclub/fsigkl.html
F-Secure Anti-Virus for MIMEsweeper 5.61 ftp://ftp.f- secure.com/support/hotfix/fsav-server/fsavsr552-16-signed.fsfix
F-Secure Messaging Security Gateway 5.0.4,
4.0.7
Packages will be available in the update channel, and installed automatically.
Protection Services For Consumers 8, 7, 6, 5 Packages will be available in the update channel, and installed automatically.
Protection Services For Businesses 3.1 Packages will be available in the update channel, and installed automatically.
F-Secure Internet Security 2009,
2008,
2007
v.7.02,
2007,
2006
Packages will be available in the update channel, and installed automatically.
F-Secure Anti-Virus 2009,
2008,
2007
v.7.02,
2007,
2006
Packages will be available in the update channel, and installed automatically.
F-Secure Home Server Security 2009 Packages will be available in the update channel, and installed automatically.

 

F-Secure deliver patches to its supported product versions that are vulnerable. See further information on supported products and F-Secure's Product Lifecycle Policy.

 

Credits

F-Secure want to thank Tamas Feher, 2F 2000 Kft., Hungary, for bringing this issue to our attention.

 

 

Date Issued: 2008-10-21
Last Updated: 2008-10-30

Get
Support

For documentation and product support,
visit our support site.

Learn More

F-Secure Community

Give advice. Get advice. Share the knowledge
on our free discussion forum.

Visit Now