First published: Tue Jul 26 2011(Updated: )
An off-by-one error was found in the way the hash manager of Clam AntiVirus, a GPL anti-virus toolkit for UNIX, performed scan of messages with certain hashes. A remote attacker could provide a message with specially-crafted hash signature in it, leading to denial of service (clamscan executable crash). Upstream bug report: [1] <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2818">https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2818</a> Relevant patch: [2] <a href="http://git.clamav.net/gitweb?p=clamav-devel.git;a=commit;h=4842733eb3f09be61caeed83778bb6679141dbc5">http://git.clamav.net/gitweb?p=clamav-devel.git;a=commit;h=4842733eb3f09be61caeed83778bb6679141dbc5</a> Other references: [3] <a href="https://bugzilla.novell.com/show_bug.cgi?id=708263">https://bugzilla.novell.com/show_bug.cgi?id=708263</a> [4] <a href="http://git.clamav.net/gitweb?p=clamav-devel.git;a=blob_plain;f=ChangeLog;hb=clamav-0.97.2">http://git.clamav.net/gitweb?p=clamav-devel.git;a=blob_plain;f=ChangeLog;hb=clamav-0.97.2</a> [5] <a href="http://www.clamav.net/lang/en/">http://www.clamav.net/lang/en/</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Clamav Clamav | =0.95.2 | |
Clamav Clamav | =0.86.2 | |
Clamav Clamav | =0.88.5 | |
Clamav Clamav | =0.02 | |
Clamav Clamav | =0.92 | |
Clamav Clamav | =0.95-rc2 | |
Clamav Clamav | =0.8-rc3 | |
Clamav Clamav | =0.15 | |
Clamav Clamav | =0.90-rc2 | |
Clamav Clamav | =0.75.1 | |
Clamav Clamav | =0.65 | |
Clamav Clamav | =0.88.7 | |
Clamav Clamav | =0.81 | |
Clamav Clamav | =0.86 | |
Clamav Clamav | =0.01 | |
Clamav Clamav | =0.92_p0 | |
Clamav Clamav | =0.97-rc | |
Clamav Clamav | =0.85 | |
Clamav Clamav | =0.84 | |
Clamav Clamav | =0.3 | |
Clamav Clamav | =0.91.2_p0 | |
Clamav Clamav | =0.93.1 | |
Clamav Clamav | =0.90-rc1.1 | |
Clamav Clamav | =0.95.1 | |
Clamav Clamav | =0.93 | |
Clamav Clamav | =0.90 | |
Clamav Clamav | =0.70-rc | |
Clamav Clamav | =0.86-rc1 | |
Clamav Clamav | =0.68.1 | |
Clamav Clamav | =0.96.4 | |
Clamav Clamav | =0.03 | |
Clamav Clamav | =0.87.1 | |
Clamav Clamav | =0.9-rc1 | |
Clamav Clamav | =0.74 | |
Clamav Clamav | =0.93.3 | |
Clamav Clamav | =0.88 | |
Clamav Clamav | =0.91-rc1 | |
Clamav Clamav | =0.86.1 | |
Clamav Clamav | =0.71 | |
Clamav Clamav | =0.88.1 | |
Clamav Clamav | =0.60p | |
Clamav Clamav | =0.94 | |
Clamav Clamav | =0.80-rc | |
Clamav Clamav | =0.91.2 | |
Clamav Clamav | =0.96.3 | |
Clamav Clamav | =0.90.3 | |
Clamav Clamav | =0.85.1 | |
Clamav Clamav | =0.90-rc1 | |
Clamav Clamav | =0.96.2 | |
Clamav Clamav | =0.95-src2 | |
Clamav Clamav | =0.13 | |
Clamav Clamav | =0.81-rc1 | |
Clamav Clamav | =0.10 | |
Clamav Clamav | =0.94.2 | |
Clamav Clamav | =0.96.1 | |
Clamav Clamav | =0.95-src1 | |
Clamav Clamav | =0.80-rc3 | |
Clamav Clamav | =0.90.1_p0 | |
Clamav Clamav | =0.12 | |
Clamav Clamav | =0.88.7_p0 | |
Clamav Clamav | =0.23 | |
Clamav Clamav | =0.84-rc1 | |
Clamav Clamav | =0.90.3_p1 | |
Clamav Clamav | =0.80-rc2 | |
Clamav Clamav | =0.80-rc1 | |
Clamav Clamav | =0.95 | |
Clamav Clamav | =0.60 | |
Clamav Clamav | =0.88.2 | |
Clamav Clamav | =0.83 | |
Clamav Clamav | =0.20 | |
Clamav Clamav | =0.80-rc4 | |
Clamav Clamav | =0.90-rc3 | |
Clamav Clamav | =0.70 | |
Clamav Clamav | =0.88.4 | |
Clamav Clamav | =0.90.3_p0 | |
Clamav Clamav | =0.14 | |
Clamav Clamav | =0.24 | |
Clamav Clamav | =0.96-rc2 | |
Clamav Clamav | =0.90.2_p0 | |
Clamav Clamav | =0.66 | |
Clamav Clamav | =0.96.5 | |
Clamav Clamav | =0.51 | |
Clamav Clamav | =0.52 | |
Clamav Clamav | =0.22 | |
Clamav Clamav | =0.72 | |
Clamav Clamav | =0.95-rc1 | |
Clamav Clamav | =0.91-rc2 | |
Clamav Clamav | =0.75 | |
Clamav Clamav | =0.05 | |
Clamav Clamav | =0.96 | |
Clamav Clamav | =0.91 | |
Clamav Clamav | =0.54 | |
Clamav Clamav | =0.96-rc1 | |
Clamav Clamav | =0.80 | |
Clamav Clamav | =0.87 | |
Clamav Clamav | =0.21 | |
Clamav Clamav | <=0.97.1 | |
Clamav Clamav | =0.84-rc2 | |
Clamav Clamav | =0.88.7_p1 | |
Clamav Clamav | =0.67-1 | |
Clamav Clamav | =0.14-pre | |
Clamav Clamav | =0.90.1 | |
Clamav Clamav | =0.91.1 | |
Clamav Clamav | =0.95.3 | |
Clamav Clamav | =0.88.3 | |
Clamav Clamav | =0.97 | |
Clamav Clamav | =0.67 | |
Clamav Clamav | =0.92.1 | |
Clamav Clamav | =0.90.2 | |
Clamav Clamav | =0.68 | |
Clamav Clamav | =0.53 | |
Clamav Clamav | =0.93.2 | |
Clamav Clamav | =0.88.6 | |
Clamav Clamav | =0.94.1 | |
Clamav Clamav | =0.80_rc | |
Clamav Clamav | =0.82 | |
Clamav Clamav | =0.73 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.