Executive brief
WithSecure Atlant is an antivirus engine used to protect Linux endpoints from malware threats. A flaw in document file processing allows an attacker to crash the antivirus engine remotely by sending a specially crafted document, disrupting the protection of affected systems. While the engine would restart automatically, the temporary outage could allow malware to slip through undetected during the brief window of unavailability.
Technical details
The vulnerability is an out-of-bounds memory read in WithSecure Atlant's Capricorn antivirus engine that occurs during the processing of document files. The flaw is triggered by sending a maliciously crafted document to a system running the affected engine; no authentication or special privileges are required—an attacker can exploit this via the network during normal antivirus scanning operations. Successful exploitation causes a denial-of-service condition by crashing the antivirus engine. The vulnerability was fixed in Capricorn engine version 2025-01-20_02 and later, with patches deployed automatically to affected Linux Endpoint Protection products.
Affected products
- WithSecure Atlant before 2025-01-20_02
Timeline
- 2025-02-07: disclosed
- 2025-01-20: patched: Capricorn engine version 2025-01-20_02 released