AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.php?compare=1&storyid=1553
Last Updated: 2006-08-07 20:33:12 UTC
"A Secunia bulletin* earlier today alerted us to a potential denial of service in the popular open-source anti-virus package ClamAV. The vulnerability is in the pefromupx() routine for unpacking a UPX packed PE executable. The advisory states that all versions up to, and including, 0.88.4 are vulnerable. The front page of http://www.clamav.net states that the latest stable version is 0.88.4, but the "stable" page only mentions 0.88.3 released last month. The sourceforge download page lists a clamav-0.88.4.tar.gz (and .sig), but at the time of this writing, actually clicking on the link results in a "file not found" error. So, it looks like they are scrambling to fix this one and the new version should be available shortly."
* http://secunia.com/advisories/21374/
Release Date: 2006-08-07
Critical: Highly critical
Impact: DoS
System access
Where: From remote
Solution Status: Unpatched…
Software: Clam AntiVirus (clamav) 0.x
…Successful exploitation crashes the service and may allow execution of arbitrary code. The vulnerability has been confirmed in versions 0.88.2 and 0.88.3. Other versions may also be affected.
Solution:
Disable the "ScanPE" option for clamd and start clamscan with the "–no-pe" option. Please note that this completely disables the scanning of PE files. Then block or filter PE files in some other way."

- http://isc.sans.org/diary.php?compare=1&storyid=1553
Last Updated: 2006-08-07 20:33:12 UTC
"A Secunia bulletin* earlier today alerted us to a potential denial of service in the popular open-source anti-virus package ClamAV. The vulnerability is in the pefromupx() routine for unpacking a UPX packed PE executable. The advisory states that all versions up to, and including, 0.88.4 are vulnerable. The front page of http://www.clamav.net states that the latest stable version is 0.88.4, but the "stable" page only mentions 0.88.3 released last month. The sourceforge download page lists a clamav-0.88.4.tar.gz (and .sig), but at the time of this writing, actually clicking on the link results in a "file not found" error. So, it looks like they are scrambling to fix this one and the new version should be available shortly."
* http://secunia.com/advisories/21374/
Release Date: 2006-08-07
Critical: Highly critical
Impact: DoS
System access
Where: From remote
Solution Status: Unpatched…
Software: Clam AntiVirus (clamav) 0.x
…Successful exploitation crashes the service and may allow execution of arbitrary code. The vulnerability has been confirmed in versions 0.88.2 and 0.88.3. Other versions may also be affected.
Solution:
Disable the "ScanPE" option for clamd and start clamscan with the "–no-pe" option. Please note that this completely disables the scanning of PE files. Then block or filter PE files in some other way."