CVE-2009-1270: High severity clamav vulnerability
Published Apr 8, 2009
·Updated
libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.
Affected Software
4 affected components
clamav clamav<0.95
Debian Debian Linux=5.0
Debian Debian Linux=4.0
Canonical Ubuntu Linux=8.10
Event History
Apr 8, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1270?
CVE-2009-1270 is classified as a denial of service vulnerability, which could lead to application hangs.
2
How do I fix CVE-2009-1270?
To fix CVE-2009-1270, upgrade ClamAV to version 0.95 or later.
3
Which versions of ClamAV are affected by CVE-2009-1270?
ClamAV versions prior to 0.95 are affected by CVE-2009-1270.
4
Is CVE-2009-1270 present in Debian or Ubuntu distributions?
Yes, CVE-2009-1270 affects Debian 4.0, 5.0 and Ubuntu 8.10.
5
What type of attack does CVE-2009-1270 facilitate?
CVE-2009-1270 facilitates a denial of service attack through crafted TAR files.