It is currently Sun May 26, 2013 1:10 am

All times are UTC




Post new topic Reply to topic  [ 4 posts ] 
Author Message
 Post subject: [Fixed]CVE-2008-1100(ClamAV)
PostPosted: Mon Apr 14, 2008 5:18 pm 
Master of the known universe
Master of the known universe
User avatar

Joined: Thu Mar 29, 2007 2:34 am
Posts: 1253
Location: Taiwan
This security issue was discovered by Secunia. It currently affects ALL versions of Clam AV. (0.92.1 is the lastest). The new release should be out soon.

Secunia Research 14/04/2008 (Mailing List) wrote:
...
Rating: Highly critical
Impact: System access
Where: From remote
...
The vulnerability is caused due to a boundary error within the
"cli_scanpe()" function in libclamav/pe.c. This can be exploited to
cause a heap-based buffer overflow via a specially crafted "Upack"
executable.
...


It seems that the vulnerable part is in the code for PE files (windows portable executables) While the possible impact to pure Linux user is unclear, you might want to switch off the ScanPE option in clam.conf before it gets fixed.

!8!


Last edited by infwonder on Tue Apr 15, 2008 11:57 pm, edited 1 time in total.

 Profile Send private message  
 
 Post subject: Re: [CVE-2008-1100]ClamAV <= 0.92.1, heap-based buffer overflow
PostPosted: Tue Apr 15, 2008 4:55 pm 
Master of the known universe
Master of the known universe
User avatar

Joined: Thu Mar 29, 2007 2:34 am
Posts: 1253
Location: Taiwan
version 0.93 (stable) is out!

This update also fix another security issue: CVE-2008-1387
Quote:
...
If you're running clamav on a mailserver, an attacker can DoS your Server remotely by sending some mails with the archive attached.
...


http://www.clamav.net/download/sources


 Profile Send private message  
 
 Post subject: Re: [CVE-2008-1100]ClamAV <= 0.92.1, heap-based buffer overflow
PostPosted: Tue Apr 15, 2008 5:54 pm 
Zenwalk Spin-offs
Zenwalk Spin-offs
User avatar

Joined: Sat Aug 19, 2006 10:52 pm
Posts: 614
Location: Annecy, FRANCE
Done.

viewtopic.php?f=37&t=15769

Emmanuel


 Profile Send private message  
 
 Post subject: Re: [CVE-2008-1100]ClamAV <= 0.92.1, heap-based buffer overflow
PostPosted: Wed Apr 16, 2008 12:24 am 
Master of the known universe
Master of the known universe
User avatar

Joined: Thu Mar 29, 2007 2:34 am
Posts: 1253
Location: Taiwan
Son|c wrote:



Thanks! \!D/


 Profile Send private message  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

All times are UTC


 Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to: