OSVDB ID: 18464

Title: Sophos Anti-Virus Visio File Processing Overflow

Info

Disclosure

Jul 28, 2005

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

A remote overflow exists in Sophos Anti-Virus. The Anti-virus engine fails to perform proper bounds checking resulting in a heap-based buffer overflow. With a specially crafted Visio file, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Rumored
Disclosure: OSVDB Verified
OSVDB: Security Software

Solution

Contact the vendor for an appropriate upgrade. An upgrade is required as there are no known workarounds.

Products

Sophos Plc

Sophos Anti-Virus for Windows

5.0.4
4.5.3
3.95

Sophos Anti-Virus for Mac OS

4.6.2
3.96

Sophos Anti-Virus for UNIX/Linux

3.95

Sophos Anti-Virus for NetWare

3.95

Sophos Anti-Virus for OS/2

3.95

Sophos Anti-Virus for OpenVMS

3.95

Sophos Anti-Virus for DOS

3.95

Sophos Anti-Virus Small Business Edition

3.95

PureMessage Small Business Edition

3.95

PureMessage for Windows/Exchange

5.0.4
3.95.0

PureMessage for UNIX

3.95.0

MailMonitor for SMTP - Windows

3.95

MailMonitor for Notes/Domino

3.95

MailMonitor for Exchange

3.95

References

Credit

  • Alex Wheeler - advisorieshustlelabs.com - Hustle Labs


Direct URL: http://osvdb.org/18464