Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

ClamAV 'libclamav/pe.c' WWPACK File Heap Based Buffer Overflow Vulnerability

ClamAV is prone to a heap-based buffer-overflow vulnerability because it fails to properly verify user-supplied data.

Successful exploits of this vulnerability can allow remote attackers to execute arbitrary machine code in the context of applications using the vulnerable 'libclamav' library. Failed exploit attempts will likely cause denial-of-service conditions.

ClamAV 0.92.1 is vulnerable to this issue; other versions may also be affected.







 

Privacy Statement
Copyright 2008, SecurityFocus