| Description: | The remote host is missing an update to clamav announced via advisory USN-672-1.
A security issue affects the following Ubuntu releases:
Ubuntu 8.10
This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.
Details follow:
Moritz Jodeit discovered that ClamAV did not correctly handle certain strings when examining a VBA project. If a remote attacker tricked ClamAV into processing a malicious VBA file, ClamAV would crash, leading to a denial of service.
Solution: The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 8.10: libclamav5 0.94.dfsg.1-1ubuntu0.1
In general, a standard system upgrade is sufficient to effect the necessary changes.
http://www.securityspace.com/smysecure/catid.html?in=USN-672-1
Risk factor : Critical |