| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.100830 |
| Kategorie: | Denial of Service |
| Titel: | ClamAV 'find_stream_bounds()' PDF File Processing Denial Of Service Vulnerability |
| Zusammenfassung: | Determine if installed ClamAV version is vulnerable |
| Beschreibung: | Overview: ClamAV is prone to a denial-of-service vulnerability because it fails to properly bounds-check specially crafted PDF files. An attacker can exploit this issue to cause denial-of-service conditions. Due to the nature of this issue, arbitrary code execution may be possible this has not been confirmed. ClamAV 0.96.2 is vulnerable other versions may also be affected. Solution: Updates are available. Please see the references for more information. References: https://www.securityfocus.com/bid/43555 http://git.clamav.net/gitweb?p=clamav-devel.git a=commitdiff h=dc5143b4669ae39c79c9af50d569c28c798f33da https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2226 http://www.clamav.net/ http://comments.gmane.org/gmane.comp.security.oss.general/3547 |
| Querverweis: |
BugTraq ID: 43555 Common Vulnerability Exposure (CVE) ID: CVE-2010-3434 http://www.openwall.com/lists/oss-security/2010/09/22/1 http://www.openwall.com/lists/oss-security/2010/09/27/6 http://www.openwall.com/lists/oss-security/2010/09/28/3 http://www.openwall.com/lists/oss-security/2010/09/28/5 http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html SuSE Security Announcement: SUSE-SR:2010:020 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.html http://www.vupen.com/english/advisories/2010/2455 |
| Copyright | This script is Copyright (C) 2010 Greenbone Networks GmbH |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|