USN-1258-1: ClamAV vulnerability

Publication date

10 November 2011

Overview

ClamAV could be made to crash or run programs as your login if it opened a specially crafted file.


Packages

  • clamav - Anti-virus utility for Unix

Details

Stephane Chazelas discovered the bytecode engine of ClamAV improperly
handled recursion under certain circumstances. This could allow a remote
attacker to craft a file that could cause ClamAV to crash, resulting in a
denial of service.

Stephane Chazelas discovered the bytecode engine of ClamAV improperly
handled recursion under certain circumstances. This could allow a remote
attacker to craft a file that could cause ClamAV to crash, resulting in a
denial of service.

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
11.10 oneiric libclamav6 –  0.97.3+dfsg-1ubuntu0.11.10.1
11.04 natty libclamav6 –  0.97.3+dfsg-1ubuntu0.11.04.1
10.10 maverick libclamav6 –  0.96.5+dfsg-1ubuntu1.10.10.3
10.04 lucid libclamav6 –  0.96.5+dfsg-1ubuntu1.10.04.3

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›