Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 217771 - app-antivirus/clamav: 2 buffer overflows and crashes/hangs (CVE-2008-1100,CVE-2008-1387)
Summary: app-antivirus/clamav: 2 buffer overflows and crashes/hangs (CVE-2008-1100,CVE...
Status: RESOLVED DUPLICATE of bug 213762
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://svn.clamav.net/svn/clamav-deve...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2008-04-15 09:47 UTC by Raphael Marichez (Falco) (RETIRED)
Modified: 2008-04-15 09:49 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Raphael Marichez (Falco) (RETIRED) gentoo-dev 2008-04-15 09:47:43 UTC
Mon Apr 14 21:35:11 CEST 2008 (tk)
----------------------------------
  * Check in 0.93 patches:
    - libclamunrar: bb#541 (RAR - Version required to extract - Evasion)
    - libclamav/spin.c: bb#876 (PeSpin Heap Overflow Vulnerability)
    - libclamav/pe.c: bb#878 (Upack Buffer Overflow Vulnerability)
    - libclamav/message.c: bb#881 (message.c: read beyond allocated region)
    - libclamav/unarj.c: bb#897 (ARJ: Sample from CERT-FI hangs clamav)
    - libclamunrar: bb#898 (RAR crashes on some fuzzed files from CERT-FI)

it's fixed in 0.93
Comment 1 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2008-04-15 09:49:05 UTC

*** This bug has been marked as a duplicate of bug 213762 ***