First published: Tue Oct 18 2011(Updated: )
A denial of service flaw was found in the way the bytecode engine of the Clam Antivirus scanner handled recursion level when scanning an unpacked file. If a local user was tricked into scanning a file or directory with 'load bytecode from the database' feature enabled, it could lead to clamscan executable crash. References: [1] <a href="https://bugs.gentoo.org/show_bug.cgi?id=387521">https://bugs.gentoo.org/show_bug.cgi?id=387521</a> [2] <a href="http://www.openwall.com/lists/oss-security/2011/10/18/1">http://www.openwall.com/lists/oss-security/2011/10/18/1</a> [3] <a href="http://git.clamav.net/gitweb?p=clamav-devel.git;a=blob_plain;f=ChangeLog;hb=clamav-0.97.3">http://git.clamav.net/gitweb?p=clamav-devel.git;a=blob_plain;f=ChangeLog;hb=clamav-0.97.3</a> Upstream patch: [4] <a href="http://git.clamav.net/gitweb?p=clamav-devel.git;a=commit;h=3d664817f6ef833a17414a4ecea42004c35cc42f">http://git.clamav.net/gitweb?p=clamav-devel.git;a=commit;h=3d664817f6ef833a17414a4ecea42004c35cc42f</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Clamav Clamav | =0.95.2 | |
Clamav Clamav | =0.92 | |
Clamav Clamav | =0.95-rc2 | |
Clamav Clamav | =0.90-rc2 | |
Clamav Clamav | =0.97-rc | |
Clamav Clamav | =0.93.1 | |
Clamav Clamav | =0.90-rc1.1 | |
Clamav Clamav | =0.95.1 | |
Clamav Clamav | <=0.97.2 | |
Clamav Clamav | =0.93 | |
Clamav Clamav | =0.90 | |
Clamav Clamav | =0.96.4 | |
Clamav Clamav | =0.9-rc1 | |
Clamav Clamav | =0.93.3 | |
Clamav Clamav | =0.91-rc1 | |
Clamav Clamav | =0.94 | |
Clamav Clamav | =0.91.2 | |
Clamav Clamav | =0.96.3 | |
Clamav Clamav | =0.90.3 | |
Clamav Clamav | =0.90-rc1 | |
Clamav Clamav | =0.96.2 | |
Clamav Clamav | =0.95-src2 | |
Clamav Clamav | =0.94.2 | |
Clamav Clamav | =0.96.1 | |
Clamav Clamav | =0.95-src1 | |
Clamav Clamav | =0.95 | |
Clamav Clamav | =0.90-rc3 | |
Clamav Clamav | =0.96-rc2 | |
Clamav Clamav | =0.96.5 | |
Clamav Clamav | =0.97.1 | |
Clamav Clamav | =0.95-rc1 | |
Clamav Clamav | =0.91-rc2 | |
Clamav Clamav | =0.96 | |
Clamav Clamav | =0.91 | |
Clamav Clamav | =0.96-rc1 | |
Clamav Clamav | =0.90.1 | |
Clamav Clamav | =0.91.1 | |
Clamav Clamav | =0.95.3 | |
Clamav Clamav | =0.97 | |
Clamav Clamav | =0.92.1 | |
Clamav Clamav | =0.90.2 | |
Clamav Clamav | =0.93.2 | |
Clamav Clamav | =0.94.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.