Vissza a www.andrews.hu-ra

    [guru] [vorlon@gentoo.org: [ GLSA 200608-13 ] ClamAV: Heap buffer overflow]


    DATE: Wed, 09 Aug 2006 16:04:30 +0200
    Damian Put heap overflow alapú sebezhetőséget talált a clamAV antivirus
    pefromupx() függvényében, a hiba a parancssori és a daemon verziót is érinti.
    
    A Gentoo kiadta a clamAV frissítését, áthidaló megoldás nincs, javasolt frissíteni.
    
    ----- Forwarded message from Matthias Geerdsen <vorlon@gentoo.org> -----
    
    From: Matthias Geerdsen <vorlon@gentoo.org>
    Date: Tue, 08 Aug 2006 16:01:42 +0200
    To: gentoo-announce@gentoo.org
    Cc: bugtraq@securityfocus.com, full-disclosure@lists.grok.org.uk,
    	security-alerts@linuxsecurity.com
    Subject: [ GLSA 200608-13 ] ClamAV: Heap buffer overflow
    
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory                           GLSA 200608-13
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                                http://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    
      Severity: High
         Title: ClamAV: Heap buffer overflow
          Date: August 08, 2006
          Bugs: #143093
            ID: 200608-13
    
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    
    Synopsis
    ========
    
    ClamAV is vulnerable to a heap-based buffer overflow resulting in a
    Denial of Service and potentially remote execution of arbitrary code.
    
    Background
    ==========
    
    ClamAV is a GPL virus scanner.
    
    Affected packages
    =================
    
        -------------------------------------------------------------------
         Package               /  Vulnerable  /                 Unaffected
        -------------------------------------------------------------------
      1  app-antivirus/clamav      < 0.88.4                      >= 0.88.4
    
    Description
    ===========
    
    Damian Put has discovered a boundary error in the pefromupx() function
    used by the UPX extraction module, which unpacks PE Windows executable
    files. Both the "clamscan" command-line utility and the "clamd" daemon
    are affected.
    
    Impact
    ======
    
    By sending a malicious attachment to a mail server running ClamAV, a
    remote attacker can cause a Denial of Service and potentially the
    execution of arbitrary code with the permissions of the user running
    ClamAV.
    
    Workaround
    ==========
    
    There is no known workaround at this time.
    
    Resolution
    ==========
    
    All ClamAV users should upgrade to the latest version:
    
        # emerge --sync
        # emerge --ask --oneshot --verbose ">=app-antivirus/clamav-0.88.4"
    
    References
    ==========
    
      [ 1 ] ClamAV security advisory
            http://www.clamav.net/security/0.88.4.html
    
    Availability
    ============
    
    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:
    
      http://security.gentoo.org/glsa/glsa-200608-13.xml
    
    Concerns?
    =========
    
    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users machines is of utmost
    importance to us. Any security concerns should be addressed to
    security@gentoo.org or alternatively, you may file a bug at
    http://bugs.gentoo.org.
    
    License
    =======
    
    Copyright 2006 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).
    
    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.
    
    http://creativecommons.org/licenses/by-sa/2.5
    
    
    
    
    ----- End forwarded message -----
    
    -- 
    
    
    

    Vissza a www.andrews.hu-ra