First published: Mon May 13 2013(Updated: )
Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an out-of-bounds read.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Canonical Ubuntu Linux | =10.04 | |
Canonical Ubuntu Linux | =11.10 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =12.10 | |
Canonical Ubuntu Linux | =13.04 | |
SUSE Linux Enterprise Server | =11.0-sp1 | |
SUSE Linux Enterprise Server | =11.0-sp2 | |
Clamav Clamav | <=0.97.7 | |
Clamav Clamav | =0.9-rc1 | |
Clamav Clamav | =0.90 | |
Clamav Clamav | =0.90-rc1 | |
Clamav Clamav | =0.90-rc1.1 | |
Clamav Clamav | =0.90-rc2 | |
Clamav Clamav | =0.90-rc3 | |
Clamav Clamav | =0.90.1 | |
Clamav Clamav | =0.90.1_p0 | |
Clamav Clamav | =0.90.2 | |
Clamav Clamav | =0.90.2_p0 | |
Clamav Clamav | =0.90.3 | |
Clamav Clamav | =0.90.3_p0 | |
Clamav Clamav | =0.90.3_p1 | |
Clamav Clamav | =0.91 | |
Clamav Clamav | =0.91-rc1 | |
Clamav Clamav | =0.91-rc2 | |
Clamav Clamav | =0.91.1 | |
Clamav Clamav | =0.91.2 | |
Clamav Clamav | =0.91.2_p0 | |
Clamav Clamav | =0.92 | |
Clamav Clamav | =0.92.1 | |
Clamav Clamav | =0.92_p0 | |
Clamav Clamav | =0.93 | |
Clamav Clamav | =0.93.1 | |
Clamav Clamav | =0.93.2 | |
Clamav Clamav | =0.93.3 | |
Clamav Clamav | =0.94 | |
Clamav Clamav | =0.94.1 | |
Clamav Clamav | =0.94.2 | |
Clamav Clamav | =0.95 | |
Clamav Clamav | =0.95-rc1 | |
Clamav Clamav | =0.95-rc2 | |
Clamav Clamav | =0.95-src1 | |
Clamav Clamav | =0.95-src2 | |
Clamav Clamav | =0.95.1 | |
Clamav Clamav | =0.95.2 | |
Clamav Clamav | =0.95.3 | |
Clamav Clamav | =0.96 | |
Clamav Clamav | =0.96-rc1 | |
Clamav Clamav | =0.96-rc2 | |
Clamav Clamav | =0.96.1 | |
Clamav Clamav | =0.96.2 | |
Clamav Clamav | =0.96.3 | |
Clamav Clamav | =0.96.4 | |
Clamav Clamav | =0.96.5 | |
Clamav Clamav | =0.97 | |
Clamav Clamav | =0.97-rc | |
Clamav Clamav | =0.97.1 | |
Clamav Clamav | =0.97.2 | |
Clamav Clamav | =0.97.3 | |
Clamav Clamav | =0.97.4 | |
Clamav Clamav | =0.97.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.