SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#363713

Clam AntiVirus contains a buffer overflow vulnerability

Overview

A buffer overflow in Clam AntiVirus (ClamAV) may allow a remote attacker to execute arbitrary code.

I. Description

Clam AntiVirus is a UNIX-based, anti-virus toolkit often deployed with mail servers to detect malicious attachments. A signedness error in ClamAV (libclamav/upx.c) may allow a buffer overflow to occur. If a remote attacker sends a specially crafted UPX-packed executable to a vulnerable ClamAV installation, that attacker may be able to trigger the buffer overflow.

II. Impact

A remote attacker may be able to execute arbitrary code with the privileges of the application linked to the ClamAV process. In addition, this vulnerability may prevent ClamAV from detecting malicious UPX-packed executables.

III. Solution

Upgrade

This issue was corrected in ClamAV 0.87.

Do not access UPX-packed executables from untrusted sources

Exploitation occurs by via specially crafted UPX-packed executables. By only accessing UPX-packed executables from trusted or known sources, the chances of exploitation are reduced.

Systems Affected

VendorStatusDate NotifiedDate Updated
Apple Computer, Inc.Unknown27-Sep-2005
Clam AntiVirusVulnerable20-Oct-2005
Conectiva Inc.Unknown21-Oct-2005
Cray Inc.Unknown21-Oct-2005
Debian LinuxVulnerable3-Nov-2005
EMC, Inc. (formerly Data General Corporation)Unknown21-Oct-2005
Engarde Secure LinuxUnknown27-Sep-2005
F5 Networks, Inc.Not Vulnerable24-Oct-2005
Fedora ProjectUnknown27-Sep-2005
FreeBSD, Inc.Vulnerable24-Oct-2005
FujitsuUnknown21-Oct-2005
Gentoo LinuxUnknown27-Sep-2005
Hewlett-Packard CompanyUnknown27-Sep-2005
HitachiNot Vulnerable24-Oct-2005
IBM CorporationUnknown27-Sep-2005
IBM Corporation (zseries)Unknown27-Sep-2005
IBM eServerUnknown27-Sep-2005
Immunix Communications, Inc.Unknown27-Sep-2005
Ingrian Networks, Inc. Unknown27-Sep-2005
Juniper Networks, Inc.Unknown21-Oct-2005
Mandriva, Inc.Vulnerable28-Sep-2005
Microsoft CorporationNot Vulnerable21-Oct-2005
MontaVista Software, Inc.Unknown27-Sep-2005
NEC CorporationUnknown21-Oct-2005
NetBSDUnknown21-Oct-2005
Novell, Inc. Unknown27-Sep-2005
OpenBSDUnknown21-Oct-2005
Openwall GNU/*/LinuxNot Vulnerable27-Sep-2005
QNX, Software Systems, Inc.Unknown21-Oct-2005
Red Hat, Inc.Not Vulnerable29-Sep-2005
Sequent Computer Systems, Inc.Unknown27-Sep-2005
Silicon Graphics, Inc.Unknown21-Oct-2005
Slackware Linux Inc.Not Vulnerable24-Oct-2005
Sony CorporationUnknown21-Oct-2005
Sun Microsystems, Inc.Not Vulnerable27-Sep-2005
SUSE LinuxUnknown27-Sep-2005
The SCO GroupUnknown21-Oct-2005
The SCO Group (SCO Linux)Unknown27-Sep-2005
Trustix Secure LinuxUnknown27-Sep-2005
TurbolinuxUnknown27-Sep-2005
UbuntuVulnerable28-Sep-2005
UnisysUnknown21-Oct-2005
Wind River Systems, Inc.Unknown21-Oct-2005

References


http://secunia.com/advisories/16848/
http://sourceforge.net/project/shownotes.php?release_id=356974
http://www.securityfocus.com/bid/14866
http://www.gentoo.org/security/en/glsa/glsa-200509-13.xml
http://www.clamav.net/
http://www.mandriva.com/security/advisories?name=MDKSA-2005:166

Credit

This vulnerability was reported by Thierry Carrez.

This document was written by Jeff Gennari.

Other Information

Date Public:2005-09-19
Date First Published:2005-10-21
Date Last Updated:2005-11-03
CERT Advisory: 
CVE-ID(s):CAN-2005-2920
NVD-ID(s):CAN-2005-2920
US-CERT Technical Alerts: 
Metric:6.75
Document Revision:45

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2005 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader