Back to list
symlink vul for Antivir / Linux Version 2.0.9-9 (maybe lower)
Jan 13 2004 06:37PM
Rene (l0om excluded org)
Re: symlink vul for Antivir / Linux Version 2.0.9-9 (maybe lower)
Jan 27 2004 02:55PM
AntiVir Support (support antivir de)
On 14 January 2004 we provided a new version of our software that was no
longer vulnerable to the exploit posted by <l0om (at) excluded (dot) org [email concealed]>. This
version was 2.0.9-11.
It was later determined that a more aggressive brute force symlink
attack would be possible with this version. Therefore, on 15 January
2004 we provided another new version of our software that no longer was
vulnerable to any symlink attacks using the temporary PID files. This
version was 2.0.9-12. Users were able to attain the updated versions
using the internet updater:
$ antivir --update
or by downloading the latest software package from the website:
Users may check their currently installed version by running:
$ antivir --version
The sigificant version information is:
product version: 2.0.9-12
This version and all subsequent versions are not vulnerable to any
symlink attacks using the temporary PID files.
Previous versions had created temporary files without first checking if
the file already existed. A check for existing files has now been added.
If the file exists, it is removed. A new file is then created using the
exclusive flag. If this is unsuccessful, no temporary file will be created.
Users should not use an NFS mount for AntiVir temporary files since file
locking over NFS does not work on most implementations. As default,
AntiVir uses /tmp or /var/tmp for temporary files.
It should be noted that H+BEDV Datentechnik GmbH was not first contacted
by <l0om (at) excluded (dot) org [email concealed]>. We learned of the problem through the bugtraq
We ask that all security-related problems be directed to
<security (at) antivir (dot) de [email concealed]> before being posted publicly. This gives us a
chance to evaluate the problem and determine a course of action without
putting our users at risk. We appreciate your cooperation.
H+BEDV Datentechnik GmbH
<mailto:support (at) antivir (dot) de [email concealed]>
Lindauer Strasse 21, 88069 Tettnang, Germany
Tel.: +49 (0)7542 500-0
Fax : +49 (0)7542 52510
[ reply ]
Copyright 2010, SecurityFocus