[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1616 clamav -- denial of service

ID: oval:org.mitre.oval:def:8026Date: (C)2009-12-15   (M)2021-06-02
Class: PATCHFamily: unix




Damian Put discovered a vulnerability in the ClamAV anti-virus toolkit's parsing of Petite-packed Win32 executables. The weakness leads to an invalid memory access, and could enable an attacker to crash clamav by supplying a maliciously crafted Petite-compressed binary for scanning. In some configurations, such as when clamav is used in combination with mail servers, this could cause a system to fail open, facilitating a follow-on viral attack. A previous version of this advisory referenced packages that were built incorrectly and omitted the intended correction. This issue was fixed in packages referenced by the -2 revision of the advisory. The Common Vulnerabilities and Exposures project identifies this weakness as CVE-2008-2713 and CVE-2008-3215.

Platform:
Debian 4.0
Product:
clamav
Reference:
DSA-1616
CVE-2008-2713
CVE-2008-3215
CVE    2
CVE-2008-2713
CVE-2008-3215
CPE    1
cpe:/o:debian:debian_linux:4.0

© SecPod Technologies