diff options
author | remko <remko@FreeBSD.org> | 2007-06-20 03:47:51 +0800 |
---|---|---|
committer | remko <remko@FreeBSD.org> | 2007-06-20 03:47:51 +0800 |
commit | e9d1019e24159eb8d82ff281486e7a5ab5bf49c4 (patch) | |
tree | 54b5c2f95673093830b5c559938ee5bb16bee64b /security/vuxml | |
parent | f210bff58e25a753a207a4108b2bf566e0153148 (diff) | |
download | freebsd-ports-gnome-e9d1019e24159eb8d82ff281486e7a5ab5bf49c4.tar.gz freebsd-ports-gnome-e9d1019e24159eb8d82ff281486e7a5ab5bf49c4.tar.zst freebsd-ports-gnome-e9d1019e24159eb8d82ff281486e7a5ab5bf49c4.zip |
Document clamav -- multiple vulnerabilities.
Diffstat (limited to 'security/vuxml')
-rw-r--r-- | security/vuxml/vuln.xml | 40 |
1 files changed, 40 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 171818e6926c..5e143f8e4d5f 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -34,6 +34,46 @@ Note: Please add new entries to the beginning of this file. --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="903654bd-1927-11dc-b8a0-02e0185f8d72"> + <topic>clamav -- multiple vulnerabilities</topic> + <affects> + <package> + <name>clamav</name> + <range><lt>0.90.3</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Clamav had been found vulnerable to multiple vulnerabilities:</p> + <ul> + <li>Improper checking for the end of an buffer causing an + unspecified attack vector.</li> + <li>Insecure temporary file handling, which could be exploited + to read sensitive information.</li> + <li>A flaw in the parser engine which could allow a remote + attacker to bypass the scanning of RAR files.</li> + <li>A flaw in libclamav/unrar.c which could cause a remote + Denial of Service (DoS) by sending a specially crafted + RAR file with a modified vm_codesize.</li> + <li>A flaw in the OLE2 parser which could cause a remote + Denial of Service (DoS).</li> + </ul> + </body> + </description> + <references> + <cvename>CVE-2007-2650</cvename> + <cvename>CVE-2007-3023</cvename> + <cvename>CVE-2007-3024</cvename> + <cvename>CVE-2007-3122</cvename> + <cvename>CVE-2007-3123</cvename> + <url>http://news.gmane.org/gmane.comp.security.virus.clamav.devel/cutoff=2853</url> + </references> + <dates> + <discovery>2007-04-18</discovery> + <entry>2007-06-19</entry> + </dates> + </vuln> + <vuln vid="8092b820-1d6f-11dc-a0b2-001921ab2fa4"> <topic>p5-Mail-SpamAssassin -- local user symlink-attack DoS vulnerability</topic> <affects> |