<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>209915</bug_id>
          <alias>CVE-2008-0318</alias>
          <creation_ts>2008-02-12 20:41 0000</creation_ts>
          <short_desc>app-antivirus/clamav &lt; 0.92.1 multiple vulnerabilities (CVE-2008-0318,CVE-2008-0728)</short_desc>
          <delta_ts>2008-02-24 19:43:21 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://secunia.com/advisories/28907/</bug_file_loc>
          <status_whiteboard>B2 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>py@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>antivirus@gentoo.org</cc>
    
    <cc>net-mail@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-02-12 20:41:50 0000</bug_when>
            <thetext>Some vulnerabilities have been reported in ClamAV, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.

1) An integer overflow error exists within the &quot;cli_scanpe()&quot; function in libclamav/pe.c. No further information is currently available.

2) An error within the &quot;unmew11()&quot; function in libclamav/mew.c can be exploited to corrupt heap memory.

Successful exploitation may allow execution of arbitrary code.

The vulnerabilities are reported in versions prior to 0.92.1.

Solution:
Update to version 0.92.1.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-02-12 20:43:27 0000</bug_when>
            <thetext>net-mail/antivirus, ok for fast-tracking stabilization of 0.92.1?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lars@chaotika.org</who>
            <bug_when>2008-02-14 16:56:51 0000</bug_when>
            <thetext>could someone please add &quot;CVE-2008-0728&quot; to the summary? (i dont have the needed permissions)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2008-02-14 19:03:10 0000</bug_when>
            <thetext>Maintainers please advise.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ticho@gentoo.org</who>
            <bug_when>2008-02-16 17:45:49 0000</bug_when>
            <thetext>I&apos;m OK for 0.92.1 stabilization.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-02-16 20:23:10 0000</bug_when>
            <thetext>Arches please test and mark stable app-antivirus/clamav-0.92.1, target &quot;alpha amd64 hppa ia64 ppc ppc64 sparc x86 ~x86-fbsd&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>maekke@gentoo.org</who>
            <bug_when>2008-02-16 20:42:45 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>angelos@gentoo.org</who>
            <bug_when>2008-02-17 13:22:20 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2008-02-18 14:57:18 0000</bug_when>
            <thetext>alpha/ia64/sparc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2008-02-18 15:45:51 0000</bug_when>
            <thetext>Stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ranger@gentoo.org</who>
            <bug_when>2008-02-18 17:27:29 0000</bug_when>
            <thetext>ppc64 done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2008-02-19 18:04:25 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-02-19 20:13:59 0000</bug_when>
            <thetext>hmm, don&apos;t know why I rated this B3 at first... glsa request filed.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2008-02-21 22:53:49 0000</bug_when>
            <thetext>GLSA 200802-09</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2008-02-24 19:43:21 0000</bug_when>
            <thetext>Fixed in release snapshot.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>