unrar.c Remote DoS in clamav 0.90

Bug #126471 reported by Leonel Nunez
256
Affects Status Importance Assigned to Milestone
clamav (Ubuntu)
Fix Released
Undecided
Unassigned
Feisty
Fix Released
Undecided
Kees Cook

Bug Description

Remote attack can cause a denial of service via crafted RAR archive in clamav 0.90
Reference : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3725

CVE References

Revision history for this message
Leonel Nunez (leonelnunez) wrote :
Revision history for this message
Leonel Nunez (leonelnunez) wrote :

The bug is on libclamav/unrar/unrarvm.c

redid the debdiff as Scott Kitterman Suggested since the change in unrar.c was only a displayed string

pbuilder builded fine installed and tested all worked
Asked for the https://wwws.clamav.net/bugzilla/attachment.cgi?id=383&action=view file to the clamav people since I don't have permissions to access it so clamav can be tested for this bug

Checking for edgy and dapper for this vulnerability

Revision history for this message
Kees Cook (kees) wrote :

Thanks! I adjusted the changelog to use the "feisty-security" pocket as well as adding a link to this bug report. I'm building it now and should have it published shortly.

Changed in clamav:
assignee: nobody → keescook
status: New → In Progress
Revision history for this message
Kees Cook (kees) wrote :

Archive admins: please sync 0.91.1-1 (or newer) from Debian. (Note that the Debian changelogs appear to be behind a few days at the moment...)

Changed in clamav:
status: New → Triaged
Revision history for this message
Leonel Nunez (leonelnunez) wrote : Re: (please sync from Debian unstable to universe) unrar.c Remote DoS in clamav before 0.91

clamav (0.90.2-0ubuntu1.3) feisty-security; urgency=low

  * SECURITY UPDATE: Remote DoS in RAR Files
  * Added 55_cve-2007-3725.dpatch: backported upstream fix (LP: #126471).
  * References
    CVE-2007-3725

 -- Leonel Nunez <email address hidden> Mon, 16 Jul 2007 21:23:43 -0600

Changed in clamav:
status: In Progress → Fix Released
Revision history for this message
Martin Pitt (pitti) wrote :

Not yet on the mirror we sync from, but someone uploaded 0.91.1-0ubuntu1 to gutsy, so that should be ok for now.

Revision history for this message
Leonel Nunez (leonelnunez) wrote :

Clamav people send me a corrupted.rar to test
Tested the unpatched clamav with the provided corrupted.rar and the unpatched version ends with a core dumped
updated to clamav 0.90.2-0ubuntu1.3 tested and all worked fine

libclamav reports :
LibClamAV Warning: RAR CRC error. Please report the bug at http://bugs.clamav.net/

Revision history for this message
Scott Kitterman (kitterman) wrote : Re: unrar.c Remote DoS in clamav before 0.91

Marked Fix Released since Gutsy already has an fixed version.

Changed in clamav:
status: Triaged → Fix Released
Revision history for this message
Leonel Nunez (leonelnunez) wrote : Re: (please sync from Debian unstable to universe) unrar.c Remote DoS in clamav before 0.91

Tested the provided corrupted.rar on dapper and and it's not vulnerable
Shows error : RAR module failure ERROR

Revision history for this message
Scott Kitterman (kitterman) wrote : Re: unrar.c Remote DoS in clamav before 0.91

Which version of clamav on Dapper?

Revision history for this message
Leonel Nunez (leonelnunez) wrote :

Tested the provided corrupted.rar on edgy with clamav 0.88.4 and and it's not vulnerable
Shows error : RAR module failure ERROR

Revision history for this message
Leonel Nunez (leonelnunez) wrote :

Scott tested with clamav 88.2-1ubuntu1.3

description: updated
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.