Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2006:067: clamav Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the clamav package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2006:067 (clamav).
Damian Put discovered an integer overflow in the PE header parser in ClamAV
that could be exploited if the ArchiveMaxFileSize option was disabled
(CVE-2006-1614). Format strings in the logging code could possibly lead to the
execution of arbitrary code (CVE-2006-1615). David Luyer found that ClamAV
could be tricked into an invalid memory access in the cli_bitset_set()
function, which could lead to a Denial of Service (CVE-2006-1630). This update
provides ClamAV 0.88.1 which corrects this issue and also fixes some other
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:067
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.