From 4128fe3c55c0dea96f2b0c1bde564a99919b7ef2 Mon Sep 17 00:00:00 2001 From: delphij Date: Fri, 12 Sep 2008 04:31:17 +0000 Subject: Document clamav CHM parser DoS issue. Approved by: portmgr (vuxml blanket) --- security/vuxml/vuln.xml | 34 ++++++++++++++++++++++++++++++++++ 1 file changed, 34 insertions(+) (limited to 'security') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 1d583cfff854..001760fc3937 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -34,6 +34,40 @@ Note: Please add new entries to the beginning of this file. --> + + clamav -- CHM Processing Denial of Service + + + clamav + 0.94 + + + clamav-devel + 20080902 + + + + +

Hanno Boeck reports:

+
+

A fuzzing test showed weakness in the chm parser of + clamav, which can possibly be exploited. The clamav + team has disabled the chm module in older versions + though freshclam updates and has released 0.94 with + a fixed parser.

+
+ +
+ + CVE-2008-1389 + https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1089 + + + 2008-07-09 + 2008-09-12 + +
+ horde -- multiple vulnerabilities -- cgit