LWN.net Logo

Pardus alert 2011-106 (clamav)

From:  Meltem Parmaksız <meltem@pardus.org.tr>
To:  pardus-security@pardus.org.tr
Subject:  [Pardus-security] [PLSA 2011-106] clamav: Denial of Service
Date:  Mon, 8 Aug 2011 16:23:18 +0300
Message-ID:  <201108081623.18486.meltem@pardus.org.tr>
Archive-link:  Article, Thread

------------------------------------------------------------------------ Pardus Linux Security Advisory 2011-106 security@pardus.org.tr ------------------------------------------------------------------------ Date: 2011-08-08 Type: Remote ------------------------------------------------------------------------ Summary ======= A vulnerability has been fixed in clamav. Description =========== CVE-2011-2721: An off-by-one error was found in the way the hash manager of Clam AntiVirus, a GPL anti-virus toolkit for UNIX, performed scan of messages with certain hashes. A remote attacker could provide a message with specially-crafted hash signature in it, leading to denial of service (clamscan executable crash). Affected packages: Pardus 2009: clamav, all before 0.97-44-15 Pardus 2011: clamav, all before 0.97.2-47-p11 Resolution ========== There are update(s) for clamav. You can update them via Package Manager or with a single command from console: Pardus 2009: pisi up clamav Pardus 2011: pisi up clamav References ========== * http://bugs.pardus.org.tr/show_bug.cgi?id=18796 ------------------------------------------------------------------------ _______________________________________________ Pardus-Security mailing list Pardus-Security@pardus.org.tr http://liste.pardus.org.tr/mailman/listinfo/pardus-security


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds