Security vulnerability in ClamAV

Bug #66510 reported by Guy Van Sanden
254
Affects Status Importance Assigned to Milestone
clamav (Ubuntu)
Fix Released
High
Unassigned
Dapper
Fix Released
High
Unassigned

Bug Description

Binary package hint: clamav

"Multiple vulnerabilities have been fixed with the release of version 0.88.5 of the free and open-source ClamAV AntiVirus product related to the handling of PE files and the unpacking of CHM help files. The PE handling issue poses a significant risk and users of versions prior to ClamAV 0.88.5 are urged to upgrade ASAP."

This would also affect Ubuntu (Dapper) as it is still at 0.88.2.

As far as I can tell, the vulnerability allows for remote exploit, so it is quite critical to fix it.

CVE References

Revision history for this message
Nicola (nicola) wrote :

Look at this bug report:

https://launchpad.net/distros/ubuntu/+source/clamav/+bug/53856

is there since July ...

seems no developer care about ...

Revision history for this message
Kees Cook (kees) wrote :
Changed in clamav:
status: Unconfirmed → Confirmed
Revision history for this message
Kees Cook (kees) wrote :

This will be fixed in edgy, and dapper will be available shortly.

Changed in clamav:
status: Confirmed → Fix Released
Revision history for this message
Martin Pitt (pitti) wrote :

Reopening, edgy is not yet fixed.

Changed in clamav:
importance: Undecided → High
status: Fix Released → In Progress
Revision history for this message
Martin Pitt (pitti) wrote :

We should also apply this to Dapper.

Changed in clamav:
importance: Undecided → High
status: Unconfirmed → In Progress
Kees Cook (kees)
Changed in clamav:
status: In Progress → Fix Released
status: In Progress → Fix Released
Revision history for this message
Kees Cook (kees) wrote :

clamav (0.88.4-1ubuntu2) edgy; urgency=low

  * SECURITY UPDATE: multiple denial of service attacks in file processors.
  * Add 'debian/patches/30_pe_chm_overflows.dpatch' to close overflows.
    Patch from Debian stable (Closes Malone #66510).
  * References
    CVE-2006-4182, CVE-2006-5295

Revision history for this message
Kees Cook (kees) wrote :

clamav (0.88.2-1ubuntu1.2) dapper-security; urgency=low

  * SECURITY UPDATE: multiple denial of service attacks in file processors.
  * Add 'debian/patches/30_pe_chm_overflows.dpatch' to close overflows.
    Patch from Debian stable (Closes Malone #66510).
  * References
    CVE-2006-4182, CVE-2006-5295

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.