ðòïåëôù 


  áòèé÷ 


Apache-Talk @lexa.ru 

Inet-Admins @info.east.ru 

Filmscanners @halftone.co.uk 

Security-alerts @yandex-team.ru 

nginx-ru @sysoev.ru 

  óôáôøé 


  ðåòóïîáìøîïå 


  ðòïçòáííù 



ðéûéôå
ðéóøíá














     áòèé÷ :: Security-alerts
Security-Alerts mailing list archive (security-alerts@yandex-team.ru)

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[security-alerts] FW: [SA25426] F-Secure Products LHA Archive Handling Buffer Overflow



> 
> TITLE:
> F-Secure Products LHA Archive Handling Buffer Overflow
> 
> SECUNIA ADVISORY ID:
> SA25426
> 
> VERIFY ADVISORY:
> http://secunia.com/advisories/25426/
> 
> CRITICAL:
> Highly critical
> 
> IMPACT:
> System access
> 
> WHERE:
> From remote
> 
> SOFTWARE:
> F-Secure Internet Security 2007
> http://secunia.com/product/14375/
> F-Secure Internet Security 2006
> http://secunia.com/product/6883/
> F-Secure Internet Security 2005
> http://secunia.com/product/4300/
> F-Secure Anti-Virus 2007
> http://secunia.com/product/14374/
> F-Secure Anti-Virus 2006
> http://secunia.com/product/6882/
> F-Secure Anti-Virus 2005
> http://secunia.com/product/4299/
> F-Secure Anti-Virus 5.x
> http://secunia.com/product/3334/
> F-Secure Anti-Virus Client Security 6.x
> http://secunia.com/product/5786/
> F-Secure Anti-Virus for Windows Servers 5.x
> http://secunia.com/product/452/
> F-Secure Anti-Virus for Workstations 5.x
> http://secunia.com/product/457/
> F-Secure Anti-Virus for Citrix Servers 5.x
> http://secunia.com/product/5198/
> F-Secure Anti-Virus for MIMEsweeper 5.x
> http://secunia.com/product/455/
> F-Secure Anti-Virus for Microsoft Exchange 6.x
> http://secunia.com/product/454/
> F-Secure Internet Gatekeeper 6.x
> http://secunia.com/product/3339/
> F-Secure Anti-Virus for Linux 4.x
> http://secunia.com/product/3165/
> F-Secure Internet Gatekeeper for Linux 2.x
> http://secunia.com/product/4635/
> 
> DESCRIPTION:
> A vulnerability has been reported in various F-Secure products, which
> can be exploited by malicious people to compromise a vulnerable
> system.
> 
> The vulnerability is caused due to a boundary error in the processing
> of LHA archives and can be exploited to cause a buffer overflow when
> decompressing a specially crafted archive.
> 
> The vulnerability is related to #1 in:
> SA21996
> 
> Successful exploitation may allow execution of arbitrary code.
> 
> SOLUTION:
> Apply hotfixes.
> 
> F-Secure Internet Security 2005 - 2007:
> Hotfix distributed automatically.
> 
> F-Secure Anti-Virus 2005 - 2007:
> Hotfix distributed automatically.
> 
> F-Secure Protection Service for Consumers:
> Hotfix distributed automatically.
> 
> F-Secure Anti-Virus for Workstations 5.44:
> ftp://ftp.f-secure.com/support/hotfix/fsavcs/fsavwk602-04-signed.fsfix
> 
> F-Secure Anti-Virus Client Security 6.00 - 6.03:
> ftp://ftp.f-secure.com/support/hotfix/fsavcs/fsavwk602-04-signed.fsfix
> 
> F-Secure Anti-Virus for Windows Servers 5.50- 5.52:
> ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsavsr552-11
> -signed.fsfix
> 
> F-Secure Anti-Virus for Citrix Servers 5.50-5.52: 
> ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsavsr552-11
> -signed.fsfix
> 
> F-Secure Anti-Virus for MIMEsweeper 5.61:
> ftp://ftp.f-secure.com/support/hotfix/fsav-server/fsavsr552-11
> -signed.fsfix
> 
> F-Secure Anti-Virus for MS Exchange 6.01:
> ftp://ftp.f-secure.com/support/hotfix/fsav-mse/fscss631-08.zip
> 
> F-Secure Anti-Virus for MS Exchange 6.40:
> http://www.f-secure.com/webclub/fsavmse6.html
> 
> F-Secure Internet Gatekeeper 6.60:
> ftp://ftp.f-secure.com/support/hotfix/fsig/fsigk660-03.zip
> 
> F-Secure Anti-Virus for Linux Servers 4.64-4.65:
> http://www.f-secure.com/webclub/fsavsrvl.html
> 
> F-Secure Anti-Virus for Linux Gateways 4.64-4.65:
> http://www.f-secure.com/webclub/fsavgwl.html
> 
> F-Secure Linux Client Security 5.30:
> http://www.f-secure.com/webclub/fscsl.html
> 
> F-Secure Linux Server Security 5.30:
> http://www.f-secure.com/webclub/fsssl.html
> 
> F-Secure Internet Gatekeeper for Linux        2.16:
> http://www.f-secure.com/webclub/fsigkl.html
> 
> PROVIDED AND/OR DISCOVERED BY:
> Originally discovered by Tavis Ormandy of Google Security Team in
> gzip.
> 
> The vendor credits Sergio Alvarez of n.runs AG for providing
> additional information.
> 
> ORIGINAL ADVISORY:
> F-Secure:
> http://www.f-secure.com/security/fsc-2007-1.shtml
> 
> OTHER REFERENCES:
> SA21996:
> http://secunia.com/advisories/21996/
> 



 




Copyright © Lexa Software, 1996-2009.