Gentoo: GLSA-200605-03: ClamAV: Buffer overflow in Freshclam
Summary
Gentoo Linux Security Advisory GLSA 200605-03
https://security.gentoo.org/
Severity: Normal
Title: ClamAV: Buffer overflow in Freshclam
Date: May 02, 2006
Bugs: #131791
ID: 200605-03
Synopsis
=======
Freshclam is vulnerable to a buffer overflow that could lead to
execution of arbitrary code.
Background
=========
ClamAV is a GPL virus scanner. Freshclam is a utility to download virus
signature updates.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 app-antivirus/clamav < 0.88.2 >= 0.88.2
==========
Ulf Harnhammar and an anonymous German researcher discovered that
Freshclam fails to check the size of the header data returned by a
webserver.
Impact
=====
...
Resolution
References
Availability
Concerns
Background