12 ms·
Bitdefender Anti-Virus: Heap Buffer Overflow via 7z LZMA
- pmoriarty 9y ago"Note also that Bitdefender’s engine is licensed to many different anti-virus vendors, all of which could be affected by this bug."
- landave 9y agoThat's right. The list of anti-virus products that license the Bitdefender engine is extremely long. Actually, I wanted to include the most prominent Bitdefender customers in the article to give an impression. I ended up not doing so, because some license partner use the Bitdefender engine with disabled archive extraction. In this case, they would not be vulnerable to this bug, and I didn't want to mislead someone into thinking they are.
- sebazzz 9y agoSo if Bitdefender develops the engine, what does the anti-virus vendor do? Only develop the input (definitions)?
- landave 9y agoThe definitions are licensed with the engine and can usually not be modified. In a nutshell, most anti-virus vendors that are licensing the Bitdefender engine extend it with their own engine to improve their detection rate. For example, they support more exotic file formats and binary packers, or fancy heuristics, etc. Essentially this means they have the full attack surface from Bitdefender plus their own attack surface...
- jimrandomh 9y agoWith most types of software, if you're stuck with C/C++, you want to keep the development to a high standard where there aren't any bugs like this. But anti-virus software is unusual in that it needs to handle malicious input of an unusually wide variety of file formats, which makes completely eliminating file-format vulnerabilities basically unfeasible without some sort of broadly-applicable fix. That fix could be a memory-safe language, or it could be sandboxing. But the assumption should be that for any antivirus product which does its file-parsing in C or C++, and which doesn't sandbox is scanning engine, there's going to be at least one critical vulnerability in the scanner. Bitdefender is still unsandboxed, so fixing this particular vulnerability is only of limited use; there are almost certainly other, similar vulnerabilities in it, so users running it are vulnerable to anyone with the resources to find one. AV companies have mostly gotten away with this sort of thing in the past, because individual AV scanners tend to have low enough market share that they aren't as desirable targets as web browsers. But Windows Defender recently broke that trend by being present on every Windows system, and having a critical vulnerability, so now there are a lot more researchers looking at unsandboxed AV scanning engines and finding problems.
- QAPereo 9y agoWhat would you recommend instead for a Win platform?
- lucian1900 9y agoNothing. There is no need for anything.
- throwaway613834 9y agoI hope you don't get downvoted through the floor for saying this, because that's the kind of reaction I've gotten the past n > 8 years for suggesting people don't run an antivirus on Windows.
- jessaustin 9y agoYou've been right for n > 8 years...
- thephyber 9y ago> There is no need for anything. This is a bit of a broad brush. It assumes that all people always act with the best security hygiene. I detest traditional AV as snake oil and realize that there is additional risk added by using AV, but it does have its place in many threat models, especially for those who are not internet+security literate.
- veeti 9y ago> Moreover, the engine runs unsandboxed and as NT Authority\SYSTEM. Is there an antivirus that _doesn't_ parse untrusted input in a process with full system privileges? What a joke.
- recentdarkness 9y agoAlready years (~7+) ago AVG introduced an out of process scanning implementation that opens the file in question with system rights however transfers the handle to a lower privileged process (restricted with ACLs) that actually performs the actual scan
- landave 9y agoThat's interesting. Unfortunately, AVG has been acquired by Avast last year [1]. I already looked into the new version of AVG a few months ago, and found that they have replaced AVG's engine with Avast's engine. Since the scanner always runs as NTAuthority\SYSTEM in the current Avast version, I would assume that the same is true for the most recent AVG version. I'm not completely sure, though, so don't quote me on that. [1]: https://press.avast.com/avast-announces-agreement-to-acquire-avg-for-13b https://press.avast.com/avast-announces-agreement-to-acquire...
- recentdarkness 9y agoWell since I am no longer involved with them for a long time, I can't really say how this all went and what is currently the state. However this piece is realtively simple to implement on windows so I can only hope they would implement the same thing for avast eventually at least. This is IMHO the only sane way to do scanning without exposing the system to a huge risk
- revelation 9y agoHaving an antivirus installed has so far consistently proven to make a system vastly less secure, degrade performance and reliably break a number of applications you might actually want to use. All of them have just fallen apart at the slightest scrutiny and they are routinely programmed by the last kind of people you want to design and implement them. The whole concept is just useless. Scanning all system IO for 20 year old BIOS viruses is a pure waste of energy.
- atomical 9y ago> I want to thank Bitdefender and especially Marius for their response as well as for fixing the bug. I don't see an update for the mac version.
- landave 9y agoBitdefender's core has dynamically loaded modules that are distributed with the regular definition update, which runs fully automatically. So there is nothing to do.
- WalterBright 9y ago"Assuming that the size is not explicitly casted, the compiler should throw a warning of the following kind:" In D, implicit truncation of an integer value is an error, not a warning. I've predicted before that lack of memory safety will be the demise of C in internet-facing programs. Dealing with the bugs is just too expensive.
- blub 9y agoIt seems like your prediction is not becoming reality. I have the following issue: I would like to be able to download a file from the internet (jpeg, pdf, mp3, mp4, etc) without the risk of getting malware on a Windows machine. Or Mac. Or Linux. Can't be done. Everything is relying on crappy C code dragging around pointers and sizes, making index calculations, calling malloc and free.
- WalterBright 9y ago> It seems like your prediction is not becoming reality. We'll see. I only made it last May :-)
- fosco 9y agoMight we agree to recommend to Microsoft users that they should use Microsoft AV. About 6 months ago we had a similar discussion [0] which arrived at that conclusion. [0] https://news.ycombinator.com/item?id=13489100 https://news.ycombinator.com/item?id=13489100
- bullen 9y agoBitdefender has problems with HTTP comet stream. Stop buying it so the company can go bankrupt.