OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Kaspersky Memory/CPU Usage Leak by design

Michael.Langjackal-net.at
Date: Fri Mar 03 2006 - 14:59:58 CST


Hi,

i've recently discovered a design problem in Kaspersky AV Scanner. Original seen on FileScanner for Unix 5.0.5 the Problematic files are also screewing up the latest 5.5.3 Version.

AS i didnt find an offical way to deploy this at Kaspersky i hope someone from them will read this
and contact me to get a POC.

Therefore not all details will be shown here to avoid massive attacks.
The file(s) are 1.6M of size and dont contain suspicous content.

calling 3 kavscanner instances already renders a P4 2.4Ghz Machine with 512Mb Ram useless after a few seconds.
A POC flashcapture is located at http://www.jackal-net.at/KasperskyLeakPOC.swf

did anyone else encountered a similar problem ?
ClamAV works fine on the same Files.

Kind Regards
Michael Lang