CVE-2008-1387 - ClamAV before 0.93 allows remote attackers to cause a denial of service (CPU consumption) via a crafted ARJ archive, as demonstrated by the PROTOS GENOME test suite for Archive Formats

Bug #223766 reported by stiV
254
Affects Status Importance Assigned to Milestone
clamav (Ubuntu)
New
Undecided
Unassigned

Bug Description

Binary package hint: clamav

see CVE page for more info - this bug practically crashes clamd and renders eg. a mailserver useless. just by sending a bad email (happened to me today)

could be a duplicate of https://bugs.launchpad.net/ubuntu/+source/clamav/+bug/218915 but i'm not sure - this really is a security issue, not something for a wishlist

CVE References

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.