GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Thu Aug 09, 2007 11:26 pm Post subject: [ GLSA 200708-04 ] ClamAV: Denial of Service |
|
|
Gentoo Linux Security Advisory
Title: ClamAV: Denial of Service (GLSA 200708-04)
Severity: normal
Exploitable: remote
Date: August 09, 2007
Bug(s): #185013
ID: 200708-04
Synopsis
A vulnerability has been discovered in ClamAV, allowing for a Denial of
Service.
Background
ClamAV is a GPL virus scanner.
Affected Packages
Package: app-antivirus/clamav
Vulnerable: < 0.91
Unaffected: >= 0.91
Architectures: All supported architectures
Description
Metaeye Security Group reported a NULL pointer dereference in ClamAV
when processing RAR archives.
Impact
A remote attacker could send a specially crafted RAR archive to the
clamd daemon, resulting in a crash and a Denial of Service.
Workaround
There is no known workaround at this time.
Resolution
All ClamAV users should upgrade to the latest version:
Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=app-antivirus/clamav-0.91" |
References
CVE-2007-3725
Last edited by GLSA on Mon Feb 13, 2012 4:24 am; edited 2 times in total |
|