Clam Anti-Virus ClamAV CAB File Handling Denial Of Service Vulnerability

Solution:
Gentoo has released advisory GLSA 200511-04 to address this issue. Gentoo updates may be applied by running the following commands as the superuser:

emerge --sync
emerge --ask --oneshot --verbose ">=app-antivirus/clamav-0.87.1"

Debian GNU/Linux has released advisory DSA 887-1 to address this, and other issues in ClamAV. Please see the referenced advisory for further information.

Mandriva Linux has released security advisory MDKSA-2005:205 with fixes addressing this and other issues. Users are advised to see the referenced advisory for details on obtaining and applying the appropriate updates.

Conectiva Linux has released security advisory CLSA-2005:1044 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.

The vendor has released version 0.87.1 of ClamAV to address this issue:


Clam Anti-Virus ClamAV 0.51

Clam Anti-Virus ClamAV 0.52

Clam Anti-Virus ClamAV 0.53

Clam Anti-Virus ClamAV 0.54

Clam Anti-Virus ClamAV 0.60

Clam Anti-Virus ClamAV 0.65

Clam Anti-Virus ClamAV 0.67

Clam Anti-Virus ClamAV 0.68

Clam Anti-Virus ClamAV 0.68 -1

Clam Anti-Virus ClamAV 0.70

Clam Anti-Virus ClamAV 0.75.1

Clam Anti-Virus ClamAV 0.80 rc4

Clam Anti-Virus ClamAV 0.80

Clam Anti-Virus ClamAV 0.80 rc3

Clam Anti-Virus ClamAV 0.80 rc1

Clam Anti-Virus ClamAV 0.80 rc2

Clam Anti-Virus ClamAV 0.81

Clam Anti-Virus ClamAV 0.82

Clam Anti-Virus ClamAV 0.83

Clam Anti-Virus ClamAV 0.84

Clam Anti-Virus ClamAV 0.84 rc1

Clam Anti-Virus ClamAV 0.84 rc2

Clam Anti-Virus ClamAV 0.85

Clam Anti-Virus ClamAV 0.85.1

Clam Anti-Virus ClamAV 0.86 .1

Clam Anti-Virus ClamAV 0.86

Clam Anti-Virus ClamAV 0.86.2

Clam Anti-Virus ClamAV 0.87


 

Privacy Statement
Copyright 2010, SecurityFocus