Para los que usan clamav

Saludos



--------------------------------------------------------------------------------

De: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] En nombre de Alertas Tempranas 
- SOC Global Crossing Latam
Enviado el: Martes, 02 de Diciembre de 2008 05:47
Para: 
Asunto: [SOC-Alert] ClamAV "cli_check_jpeg_exploit()" Denial of 
ServiceVulnerability

Date: 02 Dec 2008

Level of Risk: Medium

 

Platforms Affected: The vulnerability is reported in versions prior to 0.94.2.




Details: A vulnerability has been reported in ClamAV, which can be exploited by 
malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an infinite recursion error within the 
"cli_check_jpeg_exploit()" function in libclamav/special.c. This can be 
exploited to cause a stack overflow and crash the application via a specially 
crafted JPEG file.

 

Solution and Recommendations: Update to version 0.94.2.

 

References: http://secunia.com/advisories/32926/


 
_______________________________________________
Lista de correo Linux-plug
Temática: Discusión general sobre Linux
Peruvian Linux User Group (http://www.linux.org.pe)

Participa suscribiéndote y escribiendo a:  [email protected]
Para darte de alta, de baja  o hacer ajustes a tu suscripción visita:
http://listas.linux.org.pe/mailman/listinfo/linux-plug

IMPORTANTE: Reglas y recomendaciones
http://www.linux.org.pe/listas/reglas.php
http://www.linux.org.pe/listas/comportamiento.php
http://www.linux.org.pe/listas/recomendaciones.php

Responder a