- http://secunia.com/advisories/15835/
Release Date: 2005-06-28
Last Update: 2005-06-29
Critical: Less critical
Impact: DoS
Where: From remote … Solution:
Update to version 0.86 or later.
- http://secunia.com/advisories/16180/
Release Date: 2005-07-25
Critical: Highly critical
Impact: DoS
System access
Where: From remote…
Description:
…Some vulnerabilities in Clam AntiVirus, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
1) Two integer overflow errors in "libclamav/tnef.c" when processing TNEF files can be exploited to cause a heap-based buffer overflow via a specially crafted TNEF file with a length value of -1 in the header.
2) An integer overflow error in "libclamav/chmunpack.c" can be exploited to cause a heap-based buffer overflow via a specially crafted CHM file with a chunk entry that has a filename length of -1.
3) A boundary error in "libclamav/fsg.c" when processing a FSG compressed file can cause a heap-based buffer overflow…
The vulnerabilities have been reported in versions 0.86.1 and prior.
- http://www.clamwin.org/
("…Please note that ClamWin Free Antivirus does not include an on-access real-time scanner, that is, you need to manually scan a file in order to detect a virus. Microsoft Outlook Addin, however will delete a virus-infected attachment automatically.")
- http://secunia.com/advisories/16848/
Release Date: 2005-09-19
Critical: Highly critical
Impact: DoS, System access
Where: From remote
Solution Status: Vendor Patch
Solution: Update to version 0.87 or later…"
- http://www.clamwin.org/
"ClamWin Free Antivirus has been upgraded to include latest ClamAV virus scanning engine version 0.87. This release also fixes vulnerabilities in handling of UPX and FSG compressed executables. It includes a fix for a bug in ClamWin exclusion and inclusion filters found in versions up to 0.86.2. Please upgrade your installation by downloading the latest version using this link www.clamwin.com/download "
ClamAV 0.87.1 released, fixes multiple vulns
- http://isc.sans.org/diary.php?storyid=822
Last Updated: 2005-11-05 06:25:33 UTC
"Vulnerabilities in anti virus programs seem to be popular lately. A new version of ClamAV, 0.87.1, has been released. It addresses several security vulnerabilities. The most critical one allows remote attackers to execute arbitrary code by supplying a malformed file to vulnerable ClamAV installations. The specific flaw is in the part which unpacks executable files compressed with FSG packer v1.33. Besides this, the released version also fixes two DoS vulnerabilities published by iDefense.
Since ClamAV is often used to scan e-mail attachments on gateways (and therefore practically any user can send a malicious file which will be parsed by the gateway), although we have not yet had reports about exploits for this vulnerability, you should be proactive and install the new version.
The latest version can be downloaded from http://prdownloads.sourceforge.net/clamav/…tar.gz?download "
- http://secunia.com/advisories/18379/
Release Date: 2006-01-10
Critical: Moderately critical
Impact: Unknown
Where: From remote
Solution Status: Vendor Patch …
The vulnerability is caused due to an unspecified boundary error in "libclamav/upx.c". This can potentially be exploited to cause a heap-based buffer overflow via a specially-crafted UPX packed file. Solution:
Update to version 0.88…"
- http://clamwin.com/
"…ClamWin Free Antivirus has been upgraded to include latest ClamAV virus scanning engine version 0.88. This release fixes a possible heap overflow in the UPX code and improves zip archives handling…"