Author Topic: Kaspersky 2010 Remote Memory Corruption / DoS PoC  (Read 3420 times)

0 Members and 1 Guest are viewing this topic.

August 28, 2009, 07:46:40 pm
Read 3420 times

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
http://www.milw0rm.com/exploits/9537

Quote
Description
============

The vulnerability affects Kaspersky Internet Security 2010 9.0.0.459
antivirus and its brother, the Kaspersky Antivirus 2010 9.0.0.463
version. The exploit was discovered on August 18th 2009. The problem
with these two antivirus versions appears when parsing a URL address.
Using a lot of consecutive dots inside the address.Kaspersky's native
avp.exe process will soar CPU usage up to 100%. At first, traffic via
the browser will get blocked, and eventually, if enough consecutive dots
have been passed inside the URL address, the computer will crash. This
exploit can be used inside HTML files, as normal href values or as img
image sources. It will also work inside HTML email bodies. The code can
be used remotely, and will lead to a Remote Memory
Corruption/Denial-of-Service that could alter computer hardware or
software.
Ruining the bad guy's day

August 28, 2009, 10:24:45 pm
Reply #1

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
Just an FYI, my friend Dmitry from Kaspersky has advised me this was fixed over a week ago :)
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

August 29, 2009, 07:21:51 am
Reply #2

michajp

  • Full Member

  • Offline
  • ***

  • 59
Yes,

Some info about that case is to find there:

Code: [Select]
http://secunia.com/advisories/36405/

August 29, 2009, 12:29:49 pm
Reply #3

CM_MWR

  • Special Members
  • Hero Member

  • Offline
  • *

  • 319
Quote
Just an FYI, my friend Dmitry from Kaspersky has advised me this was fixed over a week ago

Impressive, you have friends?  :P

August 29, 2009, 02:06:48 pm
Reply #4

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net