matousec.com (site map)

Poll

Should software vendors reward independent researchers for finding vulnerabilities in their software?

  Yes, by money and credit. (78.22%)

  Yes, by credit only. (11.3%)

  No. (7.54%)

  Yes, by money only. (1.66%)

  Other answer. (1.58%)

more

results

Advisory 2007-02-15.01

Comodo DLL injection via weak hash function exploitation Vulnerability

Basic information:


Release date: February 15, 2007

Last update: February 26, 2007

Severity:Medium

Character:Privilege escalation

Status:Unknown

Testing program: BTP00005P005CF.zip

Description:

Comodo Firewall Pro (former Comodo Personal Firewall) implements a component control, which is based on a checksum comparison of process modules. Probably to achieve a better performance, cyclic redundancy check (CRC32) is used as a checksum function in its implementation. However, CRC32 was developed for error detection purposes and can not be used as a reliable cryptographic hashing function because it is possible to generate collisions in real time. The character of CRC32 allows attacker to construct a malicious module with the same CRC32 checksum as a chosen trusted module in the target system and thus bypass the protection of the component control.

Vulnerable software:

Events:

References: