[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[secure-testing-announce] [DTSA-3-1] New clamav packages fix denial of service and privilege escalation



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- -----------------------------------------------------------------------------
Debian Testing Security Advisory DTSA-3-1     http://secure-testing.debian.net
secure-testing-team@lists.alioth.debian.org                          Joey Hess
August 28th, 2005
- -----------------------------------------------------------------------------

Package        : clamav
Vulnerability  : denial of service and privilege escalation
Problem-Type   : remote
Debian-specific: no
CVE ID         : CAN-2005-2070 CAN-2005-1923 CAN-2005-2056 CAN-2005-1922 CAN-2005-2450 

Multiple security holes were found in clamav:

CAN-2005-2070

  The ClamAV Mail fILTER (clamav-milter), when used in Sendmail using long
  timeouts, allows remote attackers to cause a denial of service by keeping
  an open connection, which prevents ClamAV from reloading.

CAN-2005-1923

  The ENSURE_BITS macro in mszipd.c for Clam AntiVirus (ClamAV) allows remote
  attackers to cause a denial of service (CPU consumption by infinite loop)
  via a cabinet (CAB) file with the cffile_FolderOffset field set to 0xff,
  which causes a zero-length read.

CAN-2005-2056

  The Quantum archive decompressor in Clam AntiVirus (ClamAV) allows remote
  attackers to cause a denial of service (application crash) via a crafted
  Quantum archive.

CAN-2005-1922

  The MS-Expand file handling in Clam AntiVirus (ClamAV) allows remote
  attackers to cause a denial of service (file descriptor and memory
  consumption) via a crafted file that causes repeated errors in the
  cli_msexpand function.

CAN-2005-2450

  Multiple integer overflows in the (1) TNEF, (2) CHM, or (3) FSG file
  format processors in libclamav for Clam AntiVirus (ClamAV) allow remote
  attackers to gain privileges via a crafted e-mail message.

For the testing distribution (etch) this is fixed in version
0.86.2-4etch1.

For the unstable distribution (sid) this is fixed in version
0.86.2-1.

This upgrade is strongly recommended if you use clamav.

The Debian testing security team does not track security issues for the
stable distribution (woody). If stable is vulnerable, the Debian security
team will make an announcement once a fix is ready.

Upgrade Instructions
- --------------------

To use the Debian testing security archive, add the following lines to
your /etc/apt/sources.list:

  deb http://secure-testing.debian.net/debian-security-updates etch-proposed-updates/security-updates main contrib non-free
  deb-src http://secure-testing.debian.net/debian-security-updates etch-proposed-updates/security-updates main contrib non-free

The archive signing key can be downloaded from
http://secure-testing.debian.net/ziyi-2005-7.asc

To install the update, run this command as root:

  apt-get update && apt-get upgrade

For further information about the Debian testing security team, please refer
to http://secure-testing.debian.net/

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQFDEfAQ2tp5zXiKP0wRAoopAKCQBsKgnTGMsj5Oh6vHCsRNu3Mk2QCgg9W9
URubHaNdZR1MVdby/GIw8tc=
=KN1B
-----END PGP SIGNATURE-----


Reply to: