SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#180864

Clam AntiVirus fails to properly handle crafted Portable Executable (PE) files

Overview

A vulnerability in the way Clam AntiVirus processes Portable Executable (PE) files may lead to execution of arbitrary code.

I. Description

Clam AntiVirus is a GPL virus scanner that has built-in support for for a number of file types including PE. According to iDefense Public Advisory: 10.15.06:

    While processing certain PE elements, two variables can be very large and integer overflow could occur. This would result in less memory being allocated than was expected by the programmer and subsequent code would overflow the heap buffer.


Note that an attacker must send a specially crafted PE file through any email gateway or personal anti-virus client that employs the Clam AntiVirus scanning engine in order to exploit this vulnerability.

II. Impact

A remote, unauthenticated attacker may be able to execute arbitrary code or cause a denial of service condition.

III. Solution

Update

Clam AntiVirus has released an updated version to address this issue. Refer to File Release Notes and Changelog for Clam AntiVirus 0.88.5.

Systems Affected

VendorStatusDate NotifiedDate Updated
Clam AntiVirusVulnerable27-Oct-2006
Debian GNU/LinuxVulnerable27-Oct-2006
Gentoo LinuxVulnerable27-Oct-2006
Mandriva, Inc.Vulnerable27-Oct-2006
SUSE LinuxVulnerable27-Oct-2006
Trustix Secure LinuxVulnerable27-Oct-2006

References


http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=422
http://kolab.org/security/kolab-vendor-notice-13.txt
http://www.securityfocus.com/bid/20535
http://www.frsirt.com/english/advisories/2006/4034
http://www.frsirt.com/english/advisories/2006/4136
http://securitytracker.com/id?1017068
http://secunia.com/advisories/22370
http://secunia.com/advisories/22421
http://secunia.com/advisories/22498
http://secunia.com/advisories/22488
http://secunia.com/advisories/22537
http://xforce.iss.net/xforce/xfdb/29607

Credit

This issue was reported in File Release Notes and Changelog for Clam AntiVirus 0.88.5.

This document was written by Chris Taschner.

Other Information

Date Public:2006-10-16
Date First Published:2006-11-07
Date Last Updated:2006-11-07
CERT Advisory: 
CVE-ID(s):CVE-2006-4182
NVD-ID(s):CVE-2006-4182
US-CERT Technical Alerts: 
Metric:10.40
Document Revision:10

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2006 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader