LWN.net Logo

clamav: arbitrary code execution

Package(s):clamav CVE #(s):CVE-2011-1003
Created:March 1, 2011 Updated:April 1, 2011
Description: From the Ubuntu advisory:

It was discovered that the Microsoft Office processing code in libclamav improperly handled certain Visual Basic for Applications (VBA) data. This could allow a remote attacker to craft a document that could crash clamav or possibly execute arbitrary code.

Alerts:
Gentoo 201110-20 2011-10-23
SUSE SUSE-SR:2011:005 2011-04-01
openSUSE openSUSE-SU-2011:0208-1 2011-03-22
Fedora FEDORA-2011-2741 2011-03-05
Fedora FEDORA-2011-2743 2011-03-05
Ubuntu USN-1076-1 2011-02-28

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds