LWN.net Logo

Pardus alert 2010-55 (clamav)

From:  Eren Turkay <eren@pardus.org.tr>
To:  pardus-security@pardus.org.tr
Subject:  [Pardus-security] [PLSA 2010-55] ClamAV: Multiple Vulnerabilities
Date:  Tue, 20 Apr 2010 09:42:45 +0300 (EEST)
Message-ID:  <20100420064245.F3CA5A7AB21@lider.pardus.org.tr>
Archive-link:  Article, Thread

------------------------------------------------------------------------ Pardus Linux Security Advisory 2010-55 security@pardus.org.tr ------------------------------------------------------------------------ Date: 2010-04-20 Severity: 3 Type: Local ------------------------------------------------------------------------ Summary ======= A weakness and a vulnerability have been fixed in ClamAV, which can be exploited by malicious people to bypass the scanning functionality or potentially compromise a vulnerable system. Description =========== CVE-2010-0098: ClamAV does not properly handle the (1) CAB and (2) 7z file formats, which allows remote attackers to bypass virus detection via a crafted archive that is compatible with standard archive utilities. CVE-2010-1311: The qtm_decompress function in libclamav/mspack.c in ClamAV allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted CAB archive that uses the Quantum (aka .Q) compression format. NOTE: some of these details are obtained from third party information. Affected packages: Pardus 2009: clamav, all before 0.95.3-36-6 Pardus 2008: clamav, all before 0.95.2-31-5 Resolution ========== There are update(s) for clamav. You can update them via Package Manager or with a single command from console: Pardus 2008: pisi up clamav Pardus 2009: pisi up clamav References ========== * http://bugs.pardus.org.tr/show_bug.cgi?id=12637 * http://secunia.com/advisories/39329/ * https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1826 * https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1771 ------------------------------------------------------------------------ _______________________________________________ Pardus-security mailing list Pardus-security@pardus.org.tr http://liste.pardus.org.tr/mailman/listinfo/pardus-security


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds