-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Gentoo Linux Security Advisory GLSA 200405-03
https://security.gentoo.org/
Severity: High
Title: ClamAV VirusEvent parameter vulnerability
Date: May 11, 2004
Bugs: #46264
ID: 200405-03
Synopsis
=======
With a specific configuration (using %f in the VirusEvent parameter),
Clam AntiVirus is vulnerable to an attack allowing execution of
arbitrary commands.
Background
=========
- From http://www.clamav.net/ :
"Clam AntiVirus is a GPL anti-virus toolkit for UNIX. The main purpose
of this software is the integration with mail servers (attachment
scanning). The package provides a flexible and scalable multi-threaded
daemon, a command line scanner, and a tool for automatic updating via
Internet. The programs are based on a shared library distributed with
the Clam AntiVirus package, which you can use with your own software.
Most importantly, the virus...Read the Full Advisory
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.