Get a Pentest and security assessment of your IT network.

Advisories

iDEFENSE Security Advisory 2007-01-05.3

iDefense Security Advisory – Remote exploitation of a DoS vulnerability in Kaspersky Lab’s Antivirus could allow an attacker to cause a denial of service (DoS) condition. Kaspersky Antivirus is vulnerable to a DoS condition when processing a specially crafted PE (portable executable) file. One of the headers in a PE file is the Optional Windows Header section. This section of the PE header contains information needed by the Windows linker and loader. An invalid value for the ‘NumberOfRvaAndSizes’ field will cause Kaspersky to repeatedly seek and read from the same section of the file in an endless loop. iDefense has confirmed the existence of this vulnerability in Kaspersky Labs Antivirus Engine version 6.0 for Windows and 5.5-10 for Linux. Previous versions may also be affected. Any products that use the scanning engine are also affected. This includes the Kaspersky mail gateway scanner.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/53508/01.05.07-3.txt

Source: https://packetstormsecurity.com/files/53508/iDEFENSE-Security-Advisory-2007-01-05.3.html

Related posts
Advisories

crossZone.txt

Advisories

Secunia Security Advisory 16900

Advisories

Secunia Security Advisory 19793

Advisories

Secunia Security Advisory 22534