Joined: 12 May 2004
|Posted: Thu Sep 25, 2008 11:26 pm Post subject: [ GLSA 200809-18 ] ClamAV: Multiple Denials of Service
|Gentoo Linux Security Advisory
Title: ClamAV: Multiple Denials of Service (GLSA 200809-18)
Date: September 25, 2008
Multiple vulnerabilities in ClamAV may result in a Denial of Service.
Clam AntiVirus is a free anti-virus toolkit for UNIX, designed
especially for e-mail scanning on mail gateways.
Vulnerable: < 0.94
Unaffected: >= 0.94
Architectures: All supported architectures
Hanno boeck reported an error in libclamav/chmunpack.c when processing
CHM files (CVE-2008-1389). Other unspecified vulnerabilities were also
reported, including a NULL pointer dereference in libclamav
(CVE-2008-3912), memory leaks in freshclam/manager.c (CVE-2008-3913),
and file descriptor leaks in libclamav/others.c and libclamav/sis.c
A remote attacker could entice a user or automated system to scan a
specially crafted CHM, possibly resulting in a Denial of Service
(daemon crash). The other attack vectors mentioned above could also
result in a Denial of Service.
There is no known workaround at this time.
All ClamAV users should upgrade to the latest version:
|# emerge --sync
# emerge --ask --oneshot --verbose ">=app-antivirus/clamav-0.94"
Last edited by GLSA on Fri Jun 22, 2012 4:26 am; edited 1 time in total