Family: SuSE Local Security Checks --> Category: infos
SUSE-SA:2006:060: clamav Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the clamav package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory SUSE-SA:2006:060 (clamav).
Two security problems have been found and fixed in the anti virus
scan engine 'clamav', which could be used by remote attackers
sending prepared E-Mails containing special crafted infected files
to potentially execute code.
CVE-2006-4182: A problem in dealing with PE (Portable Executables aka
Windows .EXE) files could result in an integer overflow, causing a heap
overflow, which could be used by attackers to potentially execute code.
CVE-2006-5295: A problem in dealing with CHM (compressed help file)
exists that could cause an invalid memory read, causing the clamav
engine to crash.
Solution : http://www.suse.de/security/http://www.novell.com/linux/security/advisories/2006_60_clamav.html
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.