Jump to content

Advisories MDVSA-2010:110: clamav


Recommended Posts

Multiple vulnerabilities was discovered and fixed in clamav:

 

The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows

remote attackers to cause a denial of service (crash) via a malformed

PDF file, related to an inconsistency in the calculated stream length

and the real stream length (CVE-2010-1639).

 

Off-by-one error in the parseicon function in libclamav/pe_icons.c

in ClamAV 0.96 allows remote attackers to cause a denial of service

(crash) via a crafted PE icon that triggers an out-of-bounds read,

related to improper rounding during scaling (CVE-2010-1640).

 

Packages for 2008.0 and 2009.0 are provided as of the Extended

Maintenance Program. Please visit this link to learn more:

http://store.mandriva.com/product_info.php?cPath=149&products_id=490

 

This update provides clamav 0.96.1 which is not vulnerable to these

issues.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...