Vulnerabilities reported by iDefense in 2006
This article discusses the four vulnerabilities disclosed by iDefense in December 2006. It should be noted that these vulnerabilities represent theoretical risks, and there were no known exploits of these vulnerabilities at the time of publication (18 December, 2006).
- Petite Plugin Vulnerability
- RAR denial of service vulnerability
- CHM File heap overflow vulnerability (DoS)
- CHM name length memory consumption vulnerability (DoS)
Petite Plugin Vulnerability
A handcrafted Petite archive containing a large number of large sectors can cause a Denial of Service in the virus engine.
- You should upgrade to versions that are unaffected.
| Product Name | Affected versions | Non-affected versions | Update available |
|---|---|---|---|
| Sophos | 6.0.4 and below | 6.0.5 and above | 26/10/06 |
| Sophos Anti-Virus for Windows 2000+ | 6.0.4 and below | 6.0.5 and above | 26/10/06 |
| Sophos Endpoint Security + Application Control 2000/XP/2003 | 6.0.4 and below | 6.0.5 and above | w/c 29/10/06 |
| Sophos Endpoint Security | 6.0.4 and below | 6.0.5 and above | w/c 29/10/06 |
| Sophos | 5.2.6 and below | 5.2.7 and above | 26/10/06 |
| Sophos | 5.0.9 and below | 5.0.10 and above | w/c 29/10/06 |
| Sophos | 4.10 and below | 4.11 and above | 26/10/06 |
| Sophos | 4.10 and below | 4.11 and above | 26/10/06 |
| Sophos | 4.10 and below | 4.11 and above | 26/10/06 |
| Sophos | 4.10 and below | 4.11 and above | 26/10/06 |
| Sophos | 4.10 and below | 4.11 and above | 26/10/06 |
| Sophos | 4.10 and below | 4.11 and above | 26/10/06 |
| Sophos | 4.10 and below | 4.11 and above | 26/10/06 |
| Sophos | 4.10 and below | 4.11 and above | 26/10/06 |
| Sophos | 4.10 and below | 4.11 and above | 26/10/06 |
| Sophos | 4.10 and below | 4.11 and above | 26/10/06 |
| Sophos | 4.10 and below | 4.11 and above | 26/10/06 |
| Sophos | 4.10 and below | 4.11 and above | 26/10/06 |
| Sophos | 4.10 and below | 4.11 and above | 26/10/06 |
| Sophos | 4.10 and below | 4.11 and above | 26/10/06 |
| Sophos | 4.10 and below | 4.11 and above | 26/10/06 |
| Sophos | 4.10 and below | 4.11 and above | 26/10/06 |
| Sophos | 4.6.4 and below | 4.6.5 and above | 26/10/06 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| Sophos | 4.8.4 and below | 4.8.5 and above | 26/10/06 |
| Sophos | 4.10 and below | 4.11 and above | 26/10/06 |
| Sophos | 4.10 and below | 4.11 and above | 26/10/06 |
| PureMessage for UNIX | engine 4.11 and below | engine 4.12 and above | November 2006 |
| ES4000 | engine 4.11 and below | engine 4.12 and above | November 2006 |
Other vulnerabilities
Note: Sophos believes that these vulnerabilities pose a theoretical threat only, and will provide fixes for these in its ongoing maintenance releases.
RAR denial of service vulnerability
A malformed RAR file, handcrafted to have very specific characteristics on certain settings, will send the scanning engine into an infinite loop, consuming all processor resources. The process must be manually killed by the user.
CHM File heap overflow vulnerability (DoS)
A heap overflow will occur when scanning CHM files, if they have been crafted with a combination of very specific values for certain settings.
CHM name length memory consumption vulnerability (DoS)
A malformed CHM file with certain characteristics regarding the CHM chunk header will cause a memory corruption to occur.
- You should upgrade to versions that are unaffected.
| Product Name | Affected versions | Non - affected versions | Update available |
|---|---|---|---|
| Sophos | 6.0.5 and below | 6.0.6 and above | November 2006 |
| Sophos | 6.0.5 and below | 6.0.6 and above | November 2006 |
| Sophos Endpoint Security + Application Control 2000/XP/2003 | 6.0.5 and below | 6.0.6 and above | November 2006 |
| Sophos Endpoint Security | 6.0.5 and below | 6.0.6 and above | November 2006 |
| Sophos | 5.2.7 and below | 5.2.8 and above | November 2006 |
| Sophos | 5.0.10 and below | 5.1.0 and above | November 2006 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| Sophos | 4.6.5 and below | 4.6.6 and above | November 2006 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| Sophos | 4.8.5 and below | 4.8.6 and above | November 2006 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| Sophos | 4.11 and below | 4.12 and above | November 2006 |
| PureMessage for UNIX | engine 4.11 and below | engine 4.12 and above | November 2006 |
| ES4000 | engine 4.11 and below | engine 4.12 and above | November 2006 |
If you need more information or guidance, then please contact technical support.
- Article ID: 17609
- Created: 27 Oct 2006
- Last updated: 14 Jan 2008
