Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.1.1.2005.887
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-887-1)
Summary:The remote host is missing an update for the Debian 'clamav' package(s) announced via the DSA-887-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'clamav' package(s) announced via the DSA-887-1 advisory.

Vulnerability Insight:
Several vulnerabilities have been discovered in Clam AntiVirus, the antivirus scanner for Unix, designed for integration with mail servers to perform attachment scanning. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2005-3239

The OLE2 unpacker allows remote attackers to cause a segmentation fault via a DOC file with an invalid property tree, which triggers an infinite recursion.

CVE-2005-3303

A specially crafted executable compressed with FSG 1.33 could cause the extractor to write beyond buffer boundaries, allowing an attacker to execute arbitrary code.

CVE-2005-3500

A specially crafted CAB file could cause ClamAV to be locked in an infinite loop and use all available processor resources, resulting in a denial of service.

CVE-2005-3501

A specially crafted CAB file could cause ClamAV to be locked in an infinite loop and use all available processor resources, resulting in a denial of service.

The old stable distribution (woody) does not contain clamav packages.

For the stable distribution (sarge) these problems have been fixed in version 0.84-2.sarge.6.

For the unstable distribution (sid) these problems have been fixed in version 0.87.1-1.

We recommend that you upgrade your clamav packages.

Affected Software/OS:
'clamav' package(s) on Debian 3.1.

Solution:
Please install the updated package(s).

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-3239
BugTraq ID: 15101
http://www.securityfocus.com/bid/15101
Debian Security Information: DSA-887 (Google Search)
http://www.debian.org/security/2005/dsa-887
http://www.gentoo.org/security/en/glsa/glsa-200511-04.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2005:205
http://www.osvdb.org/20536
http://securitytracker.com/id?1015154
http://secunia.com/advisories/17184
http://secunia.com/advisories/17448
http://secunia.com/advisories/17451
http://secunia.com/advisories/17501
http://secunia.com/advisories/17559
SuSE Security Announcement: SUSE-SR:2005:026 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2005-3303
BugTraq ID: 15318
http://www.securityfocus.com/bid/15318
Bugtraq: 20051104 ZDI-05-002: Clam Antivirus Remote Code Execution (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2005-11/0041.html
http://www.zerodayinitiative.com/advisories/ZDI-05-002.html
http://www.osvdb.org/20482
http://secunia.com/advisories/17434
http://securityreason.com/securityalert/146
http://www.vupen.com/english/advisories/2005/2294
Common Vulnerability Exposure (CVE) ID: CVE-2005-3500
BugTraq ID: 15316
http://www.securityfocus.com/bid/15316
http://www.idefense.com/application/poi/display?id=333&type=vulnerabilities
http://www.osvdb.org/20483
http://securityreason.com/securityalert/152
Common Vulnerability Exposure (CVE) ID: CVE-2005-3501
BugTraq ID: 15317
http://www.securityfocus.com/bid/15317
http://www.idefense.com/application/poi/display?id=334&type=vulnerabilities
http://www.osvdb.org/20484
http://securityreason.com/securityalert/150
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.