Skip to main content

ClamAV Multiple Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 13 Feb 2008 5540 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in Clam AntiVirus (ClamAV), which could be exploited by remote attackers or malware to cause a denial of service or take complete control of an affected system.

1. Due to a heap corruption error in the "libclamav/mew.c" file when processing certain files, which could be exploited by attackers to execute arbitrary commands by tricking a vulnerable application into scanning a specially crafted file.

2. Due to an integer overflow error in the "libclamav/pe.c" file when handling certain PE files, which could be exploited to crash a vulnerable application or execute arbitrary code.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • ClamAV versions prior to 0.92.1.

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link