Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 151561
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Aarni Honka <aarni.honka@gmail.com>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 151561 depends on: Show dependency tree
Bug 151561 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-10-16 03:25 0000
TITLE:
Clam AntiVirus CHM Unpacker and PE Rebuilding Vulnerabilities

SECUNIA ADVISORY ID:
SA22370

VERIFY ADVISORY:
http://secunia.com/advisories/22370/

CRITICAL:
Highly critical

IMPACT:
DoS, System access

WHERE:
>From remote

SOFTWARE:
Clam AntiVirus (clamav) 0.x
http://secunia.com/product/2538/

DESCRIPTION:
Two vulnerabilities have been reported in Clam AntiVirus, which
potentially can be exploited by malicious people to cause a DoS
(Denial of Service) or compromise a vulnerable system.

1) An unspecified error in the CHM unpacker in chmunpack.c can be
exploited to cause a DoS.

2) An unspecified error in rebuildpe.c when rebuilding PE files after
unpacking  can be exploited to cause a heap-based buffer overflow.

SOLUTION:
Update to version 0.88.5.

PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.

ORIGINAL ADVISORY:
http://sourceforge.net/project/shownotes.php?release_id=455799

------- Comment #1 From Raphael Marichez 2006-10-16 04:26:20 0000 -------
Once again :((

But this time i didn't see any public exploit nor PoC.

Arches team, please test clamav-0.88.5 & mark stable if appropriate, thanks.

------- Comment #2 From Andrej Kacian (RETIRED) 2006-10-16 04:51:35 0000 -------
Works fine on my x86 box. Marked stable.

------- Comment #3 From Markus Rothe 2006-10-16 10:22:33 0000 -------
ppc64 stable

------- Comment #4 From Jason Wever (RETIRED) 2006-10-16 16:51:19 0000 -------
Stable on the only real 64 bit architorture.

------- Comment #5 From Tobias Scherbaum 2006-10-18 11:28:30 0000 -------
ppc stable

------- Comment #6 From René Nussbaumer 2006-10-20 01:37:41 0000 -------
Stable on hppa. Sorry for the delay. Got my machine back running.

------- Comment #7 From Raphael Marichez 2006-10-20 03:17:26 0000 -------
thanks killerfox

------- Comment #8 From Bryan Østergaard (RETIRED) 2006-10-20 04:39:50 0000 -------
Stable on Alpha + ia64.

------- Comment #9 From Raphael Marichez 2006-10-23 08:42:23 0000 -------
amd64 team ? we're late regarding the policy and the severity of this
vulnerability.

------- Comment #10 From Patrick McLean 2006-10-24 07:36:15 0000 -------
stable on amd64.

------- Comment #11 From Raphael Marichez 2006-10-24 07:39:27 0000 -------
Thanks Patrick

------- Comment #12 From Raphael Marichez 2006-10-26 15:14:33 0000 -------
GLSA 200610-10

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug