Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
[ GLSA 200404-07 ] ClamAV RAR Archive Remote Denial Of Service Vulnerability
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index News & Announcements
View previous topic :: View next topic  
Author Message
GLSA
Bodhisattva
Bodhisattva


Joined: 13 Jun 2003
Posts: 4087
Location: Dresden, Germany

PostPosted: Wed Apr 07, 2004 7:01 pm    Post subject: [ GLSA 200404-07 ] ClamAV RAR Archive Remote Denial Of Servi Reply with quote

Gentoo Linux Security Advisory

Title: ClamAV RAR Archive Remote Denial Of Service Vulnerability (GLSA 200404-07)
Severity: normal
Exploitable: remote
Date: April 07, 2004
Updated: May 22, 2006
Bug(s): #45357
ID: 200404-07

Synopsis


ClamAV is vulnerable to a denial of service attack when processing certain
RAR archives.


Background


From http://www.clamav.net/ :

"Clam AntiVirus is a GPL anti-virus toolkit for UNIX. The main purpose
of this software is the integration with mail servers (attachment
scanning). The package provides a flexible and scalable multi-threaded
daemon, a command line scanner, and a tool for automatic updating via
Internet. The programs are based on a shared library distributed with
the Clam AntiVirus package, which you can use with your own software.
Most importantly, the virus database is kept up to date."


Affected Packages

Package: app-antivirus/clamav
Vulnerable: <= 0.68
Unaffected: >= 0.68.1
Architectures: All supported architectures


Description


Certain types of RAR archives, including those created by variants of
the W32.Beagle.A@mm worm, may cause clamav to crash when it attempts to
process them.


Impact


This vulnerability causes a Denial of Service in the clamav process.
Depending on configuration, this may cause dependent services such as
mail to fail as well.


Workaround


A workaround is not currently known for this issue. All users are
advised to upgrade to the latest version of the affected package.


Resolution


ClamAV users should upgrade to version 0.68.1 or later:
Code:
# emerge sync
   
    # emerge -pv ">=app-antivirus/clamav-0.68.1"
# emerge ">=app-antivirus/clamav-0.68.1"


References

CVE-2004-1909


Last edited by GLSA on Tue Dec 03, 2013 4:16 am; edited 6 times in total
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index News & Announcements All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum