diff options
author | mnag <mnag@FreeBSD.org> | 2006-10-16 22:32:54 +0800 |
---|---|---|
committer | mnag <mnag@FreeBSD.org> | 2006-10-16 22:32:54 +0800 |
commit | 4b9d4025b8dbc00b04c180b877385d8b09e96aed (patch) | |
tree | 0c3deba6fc9aa90820a76e54ef8f229935107539 /security | |
parent | 47a8486bf33aaf7f5d09b39fb072c74780eb8737 (diff) | |
download | freebsd-ports-gnome-4b9d4025b8dbc00b04c180b877385d8b09e96aed.tar.gz freebsd-ports-gnome-4b9d4025b8dbc00b04c180b877385d8b09e96aed.tar.zst freebsd-ports-gnome-4b9d4025b8dbc00b04c180b877385d8b09e96aed.zip |
- clamav -- CHM unpacker and PE rebuilding vulnerabilities
Approved by: portmgr (mnag with secteam hat)
Diffstat (limited to 'security')
-rw-r--r-- | security/vuxml/vuln.xml | 38 |
1 files changed, 38 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 057d5727d4dc..e733a1213786 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -34,6 +34,44 @@ Note: Please add new entries to the beginning of this file. --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="8012a79d-5d21-11db-bb8d-00123ffe8333"> + <topic>clamav -- CHM unpacker and PE rebuilding vulnerabilities</topic> + <affects> + <package> + <name>clamav</name> + <range><lt>0.88.5</lt></range> + </package> + <package> + <name>clamav-devel</name> + <range><le>20060922</le></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Secunia reports:</p> + <blockquote cite="http://secunia.com/advisories/22370/"> + <p>Two vulnerabilities have been reported in Clam AntiVirus, which + potentially can be exploited by malicious people to cause a DoS + (Denial of Service) or compromise a vulnerable system.</p> + <p>1) An unspecified error in the CHM unpacker in chmunpack.c can be + exploited to cause a DoS.</p> + <p>2) An unspecified error in rebuildpe.c when rebuilding PE files + after unpacking can be exploited to cause a heap-based buffer + overflow.</p> + </blockquote> + </body> + </description> + <references> + <url>http://secunia.com/advisories/22370/</url> + <url>http://lurker.clamav.net/message/20061016.015114.dc6a8930.en.html</url> + <url>http://sourceforge.net/project/shownotes.php?release_id=455799</url> + </references> + <dates> + <discovery>2006-10-15</discovery> + <entry>2006-10-16</entry> + </dates> + </vuln> + <vuln vid="93ba13f8-5c41-11db-a5ae-00508d6a62df"> <topic>tkdiff -- temporary file symlink privilege escalation</topic> <affects> |