Description: | Description:
The remote host is missing an update to clamav announced via advisory FEDORA-2008-3358.
Update Information:
Security update - backport security fixes from 0.93: CVE-2008-1100 (#442360): Upack Processing Buffer Overflow Vulnerability CVE-2008-1387 (#442525): Endless loop / hang with crafted arj CVE-2008-0314 (#442740): PeSpin Heap Overflow Vulnerability CVE-2008-1833 (#442741): PE WWPack Heap Overflow Vulnerability
ChangeLog:
* Thu Apr 24 2008 Tomas Hoger - 0.92.1-2 - Security update - backport security fixes from 0.93: CVE-2008-1100 (#442360): Upack Processing Buffer Overflow Vulnerability CVE-2008-1387 (#442525): Endless loop / hang with crafted arj CVE-2008-0314 (#442740): PeSpin Heap Overflow Vulnerability CVE-2008-1833 (#442741): PE WWPack Heap Overflow Vulnerability
References:
[ 1 ] Bug #442740 - CVE-2008-0314 clamav: PeSpin Heap Overflow Vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=442740 [ 2 ] Bug #442741 - CVE-2008-1833 clamav: PE WWPack Heap Overflow Vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=442741 [ 3 ] Bug #442360 - CVE-2008-1100 clamav: Upack Processing Buffer Overflow Vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=442360 [ 4 ] Bug #442525 - CVE-2008-1387 clamav: Endless loop / hang with crafted arj https://bugzilla.redhat.com/show_bug.cgi?id=442525
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update clamav' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-3358
Risk factor : Critical
CVSS Score: 10.0
|