Gentoo Archives: gentoo-announce

From: Kurt Lieber <klieber@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com, security-alerts@×××××××××××××.com, gentoo-core@l.g.o
Subject: [gentoo-announce] [ GLSA 200404-07 ] ClamAV RAR Archive Remote Denial Of Service Vulnerability
Date: Wed, 07 Apr 2004 18:14:27
Message-Id: 20040407181232.GK16487@mail.lieber.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200404-07
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: ClamAV RAR Archive Remote Denial Of Service Vulnerability
9
10 Date: April 07, 2004
11 Bugs: #45357
12 ID: 200404-07
13
14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
15
16 Synopsis
17 ========
18
19 ClamAV is vulnerable to a denial of service attack when processing
20 certain RAR archives.
21
22 Background
23 ==========
24
25 From http://www.clamav.net/ :
26
27 "Clam AntiVirus is a GPL anti-virus toolkit for UNIX. The main purpose
28 of this software is the integration with mail servers (attachment
29 scanning). The package provides a flexible and scalable multi-threaded
30 daemon, a command line scanner, and a tool for automatic updating via
31 Internet. The programs are based on a shared library distributed with
32 the Clam AntiVirus package, which you can use with your own software.
33 Most importantly, the virus database is kept up to date."
34
35 Affected packages
36 =================
37
38 -------------------------------------------------------------------
39 Package / Vulnerable / Unaffected
40 -------------------------------------------------------------------
41 net-mail/clamav <= 0.68 >= 0.68.1
42
43 Description
44 ===========
45
46 Certain types of RAR archives, including those created by variants of
47 the W32.Beagle.A@mm worm, may cause clamav to crash when it attempts to
48 process them.
49
50 Impact
51 ======
52
53 This vulnerability causes a Denial of Service in the clamav process.
54 Depending on configuration, this may cause dependent services such as
55 mail to fail as well.
56
57 Workaround
58 ==========
59
60 A workaround is not currently known for this issue. All users are
61 advised to upgrade to the latest version of the affected package.
62
63 Resolution
64 ==========
65
66 ClamAV users should upgrade to version 0.68.1 or later:
67
68 # emerge sync
69
70 # emerge -pv ">=net-mail/clamav-0.68.1"
71 # emerge ">=net-mail/clamav-0.68.1"
72
73 Concerns?
74 =========
75
76 Security is a primary focus of Gentoo Linux and ensuring the
77 confidentiality and security of our users machines is of utmost
78 importance to us. Any security concerns should be addressed to
79 security@g.o or alternatively, you may file a bug at
80 http://bugs.gentoo.org.