|
ClamAV Petite Processing Denial of Service Vulnerability
|
|
Secunia Advisory:
|
SA30657
|
|
|
Release Date:
|
2008-06-17
|
|
Last Update:
|
2008-07-28
|
|
Popularity:
|
4,339 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
DoS
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Clam AntiVirus (clamav) 0.x
|
|
|
Binary Analysis:
|
BA504 :: Available for 1 Credit 
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2008-2713 CVE-2008-3215
|
|
Description: A vulnerability has been reported in ClamAV, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to a boundary error in libclamav/petite.c. This can be exploited to trigger an out-of-bounds read via a specially crafted Petite packed executable.
The vulnerability is confirmed in versions 0.93 and 0.93.1. Prior versions may also be affected.
Solution: Update to version 0.93.3.
Provided and/or discovered by: The vendor credits Damian Put.
Information about additional attack vector not patched in the original fix was provided by Secunia Research.
Changelog: 2008-06-20: Updated "Solution" section and marked the advisory as unpatched. Additional information provided by Secunia Research.
2008-07-08: Updated "Solution" and "Original Advisory" sections.
2008-07-28: Added CVE reference.
Original Advisory: https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1000
http://sourceforge.net/project/showno...?release_id=605577&group_id=86638
http://sourceforge.net/project/showno...?release_id=611890&group_id=86638
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|