Overview
The ClamAV anti-virus scanner contains a vulnerability that may allow an attacker to execute code or cause ClamAV to crash.
Description
The Portable Executable (PE) file format is a file format for executable files that is used in Microsoft Windows. PE files can be packed with executable packers, such as upack. The ClamAV anti-virus scanner can unpack and scan PE files that are packed with upack. From ClamAV bug ID 878: |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary code or cause ClamAV to crash. |
Solution
Upgrade |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Secunia Research and the ClamAV team for information that was used in this report.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2008-1100, CVE-2008-0314 |
Severity Metric: | 3.94 |
Date Public: | 2008-04-14 |
Date First Published: | 2008-04-21 |
Date Last Updated: | 2008-04-29 14:39 UTC |
Document Revision: | 31 |