Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 508
Alerts This Week
Warning Icon 1 508

Ubuntu: USN-4432-1 Critical: ClamAV Service Interruption Vulnerability

debian
Calendar Grey April 15, 2009
Scroller Debian
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ----------------------------------------------------
Several vulnerabilities have been discovered in the ClamAV anti-virus toolkit: CVE-2008-6680

Summary

Several vulnerabilities have been discovered in the ClamAV anti-virus
toolkit:

CVE-2008-6680

Attackers can cayse a denial of service (crash) via a crafted EXE
file that triggers a divide-by-zero error.

CVE-2009-1270

Attackers can cause a denial of service (infinite loop) via a
crafted tar file that causes (1) clamd and (2) clamscan to hang.

(no CVE Id yet)

Attackers can cause a denial of service (crash) via a crafted EXE
file that crashes the UPack unpacker.

For the old stable distribution (etch), these problems have been fixed
in version 0.90.1dfsg-4etch19.

For the stable distribution (lenny), these problems have been fixed in
version 0.94.dfsg.2-1lenny2.

For the unstable distribution (sid), these problems have been fixed in
version 0.95.1+dfsg-1.

We recommend that you upgrade your clamav packages.

Upgrade instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package ...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: clamav

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.