Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Debian 3.1: DSA-888-1 Urgent: Several ClamAV Security Issues

debian
Calendar Grey November 7, 2005
Scroller Debian
- --------------------------------------------------------------------------Debian Security Advisory
Updated package.

Summary


The OLE2 unpacker allows remote attackers to cause a segmentation
fault via a DOC file with an invalid property tree, which triggers
an infinite recursion.

CVE-2005-3303

A specially crafted executable compressed with FSG 1.33 could
cause the extractor to write beyond buffer boundaries, allowing an
attacker to execute arbitrary code.

CVE-2005-3500

A specially crafted CAB file could cause ClamAV to be locked in an
infinite loop and use all available processor resources, resulting
in a denial of service.

CVE-2005-3501

A specially crafted CAB file could cause ClamAV to be locked in an
infinite loop and use all available processor resources, resulting
in a denial of service.

The old stable distribution (woody) does not contain clamav packages.

For the stable distribution (sarge) these problems have been fixed in
version 0.84-2.sarge.6.

For the unstable distribution (sid) these problems have been fixed in
version 0.87.1-1.

We reco...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.