ClamAV Multiple Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in Clam AntiVirus (ClamAV), which could be exploited by remote attackers or malware to cause a denial of service or take complete control of an affected system.
1. Due to a heap corruption error in the "libclamav/mew.c" file when processing certain files, which could be exploited by attackers to execute arbitrary commands by tricking a vulnerable application into scanning a specially crafted file.
2. Due to an integer overflow error in the "libclamav/pe.c" file when handling certain PE files, which could be exploited to crash a vulnerable application or execute arbitrary code.
Impact
- Denial of Service
- Remote Code Execution
System / Technologies affected
- ClamAV versions prior to 0.92.1.
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 0.92.1.
http://sourceforge.net/project/shownotes.php?release_id=575703
Vulnerability Identifier
Source
Related Link
Share with