*** This bug is a security vulnerability ***

Public security bug reported:

Binary package hint: clamav

see http://secunia.com/secunia_research/2008-11/advisory/

there is no fix available, but should be soon.

"Secunia Research has discovered a vulnerability in ClamAV, which can 
be exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused due to a boundary error within the 
"cli_scanpe()" function in libclamav/pe.c. This can be exploited to 
cause a heap-based buffer overflow via a specially crafted "Upack" 
executable.

Successful exploitation allows execution of arbitrary code."

** Affects: clamav (Ubuntu)
     Importance: Undecided
         Status: New

** Visibility changed to: Public

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2008-1100

-- 
ClamAV Upack Processing Buffer Overflow Vulnerability
https://bugs.launchpad.net/bugs/217256
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to