Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] Sophos Antivirus Library Remote Heap Overflow |
|---|---|
| Date: | Fri, 26 Aug 2005 12:36:01 +0000 |
Date August 26, 2005 Vulnerability The Sophos Antivirus Library provides file format support for virus analysis. During analysis of Visio files Sophos is vulnerable to a heap overflow allowing attackers complete control of the system(s) being protected. This vulnerability can be exploited remotely without user interaction or authentication through common protocols such as SMTP, SMB, HTTP, FTP, etc. Impact Successful exploitation of Sophos protected systems allows attackers unauthorized control of data and related privileges. It also provides leverage for further network compromise. Sophos Antivirus Library implementations are likely vulnerable in their default configuration. Affected Products Sophos Antivirus for Windows 2000/XP/2003 Sophos Antivirus for Windows NT Sophos Antivirus for Mac OS X Sophos Antivirus for MAC 8/9 Sophos Antivirus for UNIX/Linux Sophos Antivirus for Netware Sophos Antivirus for OS/2 Sophos Antivirus for OpenVMS Sophos Antivirus for DOS/Windows 3.1x Sophos Antivirus Small Business Edition for Windows Sophos Antivirus Small Business Edition for Mac PureMessage Small Business Edition PureMessage for Windows/Exchange PureMessage for UNIX MailMonitor for SMTP â Windows MailMonitor for Notes/Domino MailMonitor for Exchange The Sophos Antivirus Library is also OEM by over 25 other vendors with products that are affected by this vulnerability; see the following link for a list. There are also several vendors not listed that OEM the Sophos Antivirus Library. Refer to Sophos or your vendor for specifics. http://www.sophos.com/partners/oem/ Credit This vulnerability was discovered and researched by Alex Wheeler. Contact security@rem0te.com Details http://www.rem0te.com/public/images/sophos.pdf _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-disclosure] Re: MS05_039 Exploitation (different languages), Sanjay Rawat |
|---|---|
| Next by Date: | [Full-disclosure] Re: MS05_039 Exploitation (different languages), Roman Medina-Heigl Hernandez |
| Previous by Thread: | [Full-disclosure] [ GLSA 200508-18 ] PhpWiki: Arbitrary command execution through XML-RPC, Thierry Carrez |
| Next by Thread: | [Full-disclosure] [USN-174-1] courier vulnerability, Martin Pitt |
| Indexes: | [Date] [Thread] [Top] [All Lists] |