Gentoo Archives: gentoo-announce

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200506-23 ] Clam AntiVirus: Denial of Service vulnerability
Date: Mon, 27 Jun 2005 04:43:08
Message-Id: 200506270617.32076.jaervosz@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200506-23
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Clam AntiVirus: Denial of Service vulnerability
9 Date: June 27, 2005
10 Bugs: #96960
11 ID: 200506-23
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Clam AntiVirus is vulnerable to a Denial of Service attack when
19 processing certain Quantum archives.
20
21 Background
22 ==========
23
24 Clam AntiVirus is a GPL anti-virus toolkit, designed for integration
25 with mail servers to perform attachment scanning. Clam AntiVirus also
26 provides a command line scanner and a tool for fetching updates of the
27 virus database.
28
29 Affected packages
30 =================
31
32 -------------------------------------------------------------------
33 Package / Vulnerable / Unaffected
34 -------------------------------------------------------------------
35 1 app-antivirus/clamav < 0.86.1 >= 0.86.1
36
37 Description
38 ===========
39
40 Andrew Toller and Stefan Kanthak discovered that a flaw in libmspack's
41 Quantum archive decompressor renders Clam AntiVirus vulnerable to a
42 Denial of Service attack.
43
44 Impact
45 ======
46
47 A remote attacker could exploit this vulnerability to cause a Denial of
48 Service by sending a specially crafted Quantum archive to the server.
49
50 Workaround
51 ==========
52
53 There is no known workaround at this time.
54
55 Resolution
56 ==========
57
58 All Clam AntiVirus users should upgrade to the latest available
59 version:
60
61 # emerge --sync
62 # emerge --ask --oneshot --verbose ">=app-antivirus/clamav-0.86.1"
63
64 References
65 ==========
66
67 [ 1 ] Clam AntiVirus Release Notes
68 http://sourceforge.net/project/shownotes.php?release_id=337279
69
70 Availability
71 ============
72
73 This GLSA and any updates to it are available for viewing at
74 the Gentoo Security Website:
75
76 http://security.gentoo.org/glsa/glsa-200506-23.xml
77
78 Concerns?
79 =========
80
81 Security is a primary focus of Gentoo Linux and ensuring the
82 confidentiality and security of our users machines is of utmost
83 importance to us. Any security concerns should be addressed to
84 security@g.o or alternatively, you may file a bug at
85 http://bugs.gentoo.org.
86
87 License
88 =======
89
90 Copyright 2005 Gentoo Foundation, Inc; referenced text
91 belongs to its owner(s).
92
93 The contents of this document are licensed under the
94 Creative Commons - Attribution / Share Alike license.
95
96 http://creativecommons.org/licenses/by-sa/2.0