First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 106279
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Carsten Lohrke <carlo@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 106279 depends on: Show dependency tree
Bug 106279 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-09-17 07:54 0000
Two vulnerabilities were identified in Clam AntiVirus (ClamAV), which could be
exploited by remote attackers or malware to execute arbitrary commands or cause
a denial of service.

The first issue is due to a buffer overflow error in "libclamav/upx.c" when
processing malformed UPX-packed executables, which could be exploited by
attackers to compromise a vulnerable system by sending, to a vulnerable
application, emails containing specially crafted files.

The second issue is due to an error in "libclamav/fsg.c" when processing
specially crafted FSG-packed executables, which could be exploited by attackers
to cause the application to enter an infinite loop.

http://www.frsirt.com/english/advisories/2005/1774


update to 0.87 available

------- Comment #1 From Andrej Kacian (RETIRED) 2005-09-17 08:51:39 0000 -------
clamav-0.87 is already in portage, all arch keywords bumped to unstable. I can
stabilize x86, as well as amd64, as I'm using clamav on both arches quite
extensively.

------- Comment #2 From Thierry Carrez (RETIRED) 2005-09-17 09:26:39 0000 -------
Archs, test and mark stable :
Target KEYWORDS="alpha amd64 hppa ia64 ppc ppc64 sparc x86"

Andrej: feel free to mark on archs you test on, just remove them from Cc: if you do.

------- Comment #3 From Andrej Kacian (RETIRED) 2005-09-17 09:42:58 0000 -------
Stable on x86 and amd64.

------- Comment #4 From Michael Hanselmann (hansmi) (RETIRED) 2005-09-17 11:15:48 0000 -------
Stable on ppc and hppa.

------- Comment #5 From Jason Wever (RETIRED) 2005-09-17 17:37:49 0000 -------
Stable on SPARC.

------- Comment #6 From Bryan Østergaard (RETIRED) 2005-09-17 19:26:04 0000 -------
Stable on alpha.

------- Comment #7 From Markus Rothe 2005-09-18 00:07:47 0000 -------
stable on ppc64 

------- Comment #8 From Thierry Carrez (RETIRED) 2005-09-19 01:48:16 0000 -------
GLSA 200509-13
ia64 should mark stable to benefit from GLSA

First Last Prev Next    No search results available      Search page      Enter new bug