Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Gentoo: GLSA-200405-03 High: ClamAV VirusEvent Command Execution Attack

gentoo
Calendar Grey May 11, 2004
Dist Gentoo Esm H88
ClamAV security bulletin highlights a critical command execution flaw stemming from improper management of parameters in VirusEvent processing.
With a specific configuration (using %f in the VirusEvent parameter), Clam AntiVirus is vulnerable to an attack allowing execution of arbitrary commands

Summary

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Gentoo Linux Security Advisory                           GLSA 200405-03
                                            https://security.gentoo.org/

Severity: High Title: ClamAV VirusEvent parameter vulnerability Date: May 11, 2004 Bugs: #46264 ID: 200405-03

Synopsis ======= With a specific configuration (using %f in the VirusEvent parameter), Clam AntiVirus is vulnerable to an attack allowing execution of arbitrary commands.
Background ========= - From http://www.clamav.net/ :
"Clam AntiVirus is a GPL anti-virus toolkit for UNIX. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a command line scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use with your own software. Most importantly, the virus...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Your message here