Bird_banner_small4
Sophos Anti-Virus RAR VMSF_DELTA Filter Signedness Error
TSL ID TSL20121207-01
CVE ID(s) Not available.
Severity High
Description

An signedness error vulnerability exists in Sophos Anti-Virus. The vulnerability is due to insufficient validation of one of the parameters of the VMSF_DELTA filter while parsing RAR files. The vulnerable code calculates new values from this parameter resulting in a memory corruption.

A remote attacker could exploit this vulnerability by causing Sophos Anti-Virus to process a specially crafted RAR file. Successful exploitation could result in arbitrary code execution in the context of the affected service, which is SYSTEM by default.

Sophos released the following advisory regarding this issue:

http://www.sophos.com/en-us/support/knowledgebase/118424.aspx#five

Affected Products
  • Sophos Threat Detection Engine Prior to 3.37.2
CVSS Score Base 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C):
  • Access vector is NETWORK
  • Access complexity is MEDIUM
  • Level of authentication required is NONE
  • Impact of this vulnerability on data confidentiality is COMPLETE
  • Impact of this vulnerability on data integrity is COMPLETE
  • Impact of this vulnerability on data availability is COMPLETE
Temporal 6.9 (E:U/RL:OF/RC:C):
  • The exploitability level of this vulnerability is UNPROVEN
  • The remediation level of this vulnerability is OFFICIAL FIX
  • The report confidence level of this vulnerability is CONFIRMED
Identifiers
OSVDB
SecurityTracker
References https://lock.cmpxchg8b.com/sophailv2.pdf
http://www.sophos.com/en-us/support/knowledgebase/118424.aspx#six
Related Threats