Package: clamav
Version: 0.96+dfsg-4~volatile1

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1640

Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV
0.96 allows remote attackers to cause a denial of service (crash) via a
crafted PE icon that triggers an out-of-bounds read, related to improper
rounding during scaling. 

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1639

The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows
remote attackers to cause a denial of service (crash) via a malformed PDF
file, related to an inconsistency in the calculated stream length and the
real stream length. 

FIX:

New version (0.96.1) contain all fixes of the bugs mentioned above.



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to