This is posted after vendor notifidation. I personaly know of several license being paid for and activly deployed. Thsi is only being posted here as this is RC software and not "Gold" distribution
Subject: CPU process exhaustion leading to DOS vulnerability and
apparent file corruption
Importance: High
https://community.sophos.com/products/unified-threat-management/astaroorg/f/58/t/54396
ew=collapsed&sb=5&o=&fpart=1#39955
https://community.sophos.com/products/unified-threat-management/astaroorg/f/60/t/56251
ew=collapsed&sb=5&o=&fpart=1#39715
I have never notified before so bear with me:
Tested Hardware: p-2 350 with 192 megs ram.
system parameters: system loads stay below 1.0(averaging .6-.9) with
spikes to 1.3 or so during midnight logs compression runs.
number of ips in use:2
configuration: http proxy, dns proxy, NAT, pop3 proxy with two mail
addresses in expression filter and 6 file types in attachment filter
with no a/v license, DHCP.
versions vulnerable: v5.001
versions possibly vulnerable but not tested: v5.000
Vulnerability type: DOS via cpu exhaustion of processe's resources
leading to apparent file corruption.
Rest of machine unaffected except for system wide slowdown.
parameters. have pop3 proxy set to scan all pop3
traffic...a/v does not
have to be on for this to take effect.
compose an e-mail then attach a file at least 500kilobytes in
size. send
it to an external pop3 account. now use a mail client to check that
pop3 account. The instant the pop3 proxy gets that mail that pop3
session will hang on that message and cpu load will skyrocket. no
further pop3 activity will be possible until the pop3 proxy
either times
out or successfully retrieves the message(on my machine it
took up to 5
minutes).
Mitigation steps taken: tried to install the v5 mr. popper file into
v5.001. no effect.
Aggravating factors: if multiple pop3 accesses are being
performed this
cpu loading effect is cumulative. I have tried this with 5 pop3
accounts at once and while not able to bring the box to a
halt pop3 was
out of commission for about 5 minutes. Further testing revelaed
apparent file corruption as testing with 8 simultaneuos pop3 accounts
led to scanner errors and the pop3 scanner being
non-functional at all
for all pop3 accounts. I decided to really hit this hard. I sent that 500k
attachment to all 8 of my pop3 accounts then hit all 8 at the
same time. This lead to the scanner errors noted in v5. The
only to fix this(for me) was to reload astaro 5.001 from
scratch and import my backup. I then hit all 8 pop3 accounts
again. same issue. I have now has to completely disable the
pop3 proxy due to apparent file corruption. After letting it sit for a few days with the pop3 proxy off apparently the file finally got cleared from memory and is functiong again. However the next time I received an attachment within the paramenters of the advisory the pop3 proxy died and had to be shut down once again.
Workarounds: disable pop3 proxy or disallow all attachments on the network.
Vendor notified: 041804 2212 EDT.
Vendor acknowledgment: 042002 4:20 AM EDT.
This thread was automatically locked due to age.