Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 232665
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 232665 depends on: 189319 Show dependency tree
Bug 232665 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-07-22 16:05 0000
CVE-2008-3243 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3243):
  Multiple unspecified vulnerabilities in the scanning engine before 4.4.4 in
  F-Prot Antivirus before 6.0.9.0 allow remote attackers to cause a denial of
  service via (1) a crafted UPX-compressed file, which triggers an engine
  crash; (2) a crafted Microsoft Office file, which triggers an infinite loop;
  or (3) an ASPack-compressed file, which triggers an engine crash.

CVE-2008-3244 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3244):
  The scanning engine before 4.4.4 in F-Prot Antivirus before 6.0.9.0 allows
  remote attackers to cause a denial of service (engine crash) via a CHM file
  with a large nb_dir value that triggers an out-of-bounds read.

------- Comment #1 From Robert Buchholz 2008-07-22 16:06:56 0000 -------
Linux 6.0.2 changelog states:

 - Scan engine upgraded from 4.4.2 to 4.4.4 with improved detection rates and
fewer false positives. 

------- Comment #2 From Robert Buchholz 2008-10-04 19:12:29 0000 -------
ping, please bump

------- Comment #3 From Stefan Behte 2008-11-30 17:42:43 0000 -------
*PING #2* 

------- Comment #4 From Fabian Groffen 2009-04-02 15:36:45 0000 -------
versions bumped.  since there are no 6.0.2 versions for ppc and x86-fbsd, I
guess I won't ask for them to be keyworded, hoping frisk will eventually update
those as well.

------- Comment #5 From Pierre-Yves Rofes 2009-04-17 09:00:06 0000 -------
This has been fixed with GLSA 200904-14. Since impact and versions are the
same, no errata will be sent. glsa-200904-14.xml has been updated. Thanks.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug