Joined: 12 May 2004
|Posted: Thu Aug 09, 2007 11:26 pm Post subject: [ GLSA 200708-04 ] ClamAV: Denial of Service
|Gentoo Linux Security Advisory
Title: ClamAV: Denial of Service (GLSA 200708-04)
Date: August 09, 2007
A vulnerability has been discovered in ClamAV, allowing for a Denial of
ClamAV is a GPL virus scanner.
Vulnerable: < 0.91
Unaffected: >= 0.91
Architectures: All supported architectures
Metaeye Security Group reported a NULL pointer dereference in ClamAV
when processing RAR archives.
A remote attacker could send a specially crafted RAR archive to the
clamd daemon, resulting in a crash and a Denial of Service.
There is no known workaround at this time.
All ClamAV users should upgrade to the latest version:
|# emerge --sync
# emerge --ask --oneshot --verbose ">=app-antivirus/clamav-0.91"
Last edited by GLSA on Mon Feb 13, 2012 4:24 am; edited 2 times in total