LWN.net Logo

clamav: denial of service

Package(s):clamav CVE #(s):CVE-2010-0098
Created:April 9, 2010 Updated:September 8, 2010
Description: From the Ubuntu advisory:

It was discovered that ClamAV did not properly verify its input when processing CAB files. A remote attacker could send a specially crafted CAB file to evade malware detection. (CVE-2010-0098)

It was discovered that ClamAV did not properly verify its input when processing CAB files. A remote attacker could send a specially crafted CAB file and cause a denial of service via application crash.

Alerts:
Gentoo 201009-06 2010-09-07
Mandriva MDVSA-2010:082-1 2010-05-20
SuSE SUSE-SR:2010:010 2010-04-27
Pardus 2010-55 2010-04-20
Mandriva MDVSA-2010:082 2010-04-18
Ubuntu USN-926-1 2010-04-08

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds