Integer overflow in libclamav in ClamAV before 0.92.1, as used in clamd, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Petite packed PE file, which triggers a heap-based buffer overflow.
Posted Feb 16, 2008 20:44 UTC (Sat) by kitterma (guest, #4448)
[Link]
FYI, the Ubuntu packages are all updated for these issues too, but don't get Ubuntu Security
Notices (USN) because they aren't in the Main Ubuntu repository.