Gentoo: GLSA-200612-18: ClamAV: Denial of Service
Summary
Gentoo Linux Security Advisory GLSA 200612-18
https://security.gentoo.org/
Severity: Normal
Title: ClamAV: Denial of Service
Date: December 18, 2006
Bugs: #157698
ID: 200612-18
Synopsis
=======
ClamAV is vulnerable to Denial of Service.
Background
=========
ClamAV is a GPL virus scanner.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 app-antivirus/clamav < 0.88.7 >= 0.88.7
==========
Hendrik Weimer discovered that ClamAV fails to properly handle deeply
nested MIME multipart/mixed content.
Impact
=====
By sending a specially crafted email with deeply nested MIME
multipart/mixed content an attacker could cause ClamAV to crash.
Workaround
=========
There ...
Resolution
References
Availability
Concerns
Background