|
Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2005:205: clamav Vulnerability Scan
Vulnerability Scan Summary Check for the version of the clamav package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2005:205 (clamav).
A number of vulnerabilities were discovered in ClamAV versions prior to 0.87.1:
The OLE2 unpacker in clamd allows remote attackers to cause a DoS (segfault)
via a DOC file with an invalid property tree (CVE-2005-3239) The FSG unpacker
allows remote attackers to cause 'memory corruption' and execute arbitrary code
via a crafted FSG 1.33 file (CVE-2005-3303) The tnef_attachment() function
allows remote attackers to cause a DoS (infinite loop and memory exhaustion)
via a crafted value in a CAB file that causes ClamAV to repeatedly scan the
same block (CVE-2005-3500) Remote attackers could cause a DoS (infinite loop)
via a crafted CAB file (CVE-2005-3501) An improper bounds check in petite.c
could allow attackers to perform unknown attacks via unknown vectors
(CVE-2005-3587) This update provides ClamAV 0.87.1 which corrects all of these
issues.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:205
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|