Jump to content

Advisories MDKSA-2007:043: Updated clamav packages address multiple issues.


paul
 Share

Recommended Posts

Clam AntiVirus ClamAV before 0.90 does not close open file descriptors

under certain conditions, which allows remote attackers to cause a

denial of service (file descriptor consumption and failed scans) via

CAB archives with a cabinet header record length of zero, which causes

a function to return without closing a file descriptor. (CVE-2007-0897)

 

Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV

before 0.90 allows remote attackers to overwrite arbitrary files via a

.. (dot dot) in the id MIME header parameter in a multi-part message.

(CVE-2007-0898)

 

The update to 0.90 addresses these issues.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...