Clam Anti-Virus ClamAV ZIP File Parsing Remote Denial Of Service Vulnerability
BID:12408
Info
Clam Anti-Virus ClamAV ZIP File Parsing Remote Denial Of Service Vulnerability
| Bugtraq ID: | 12408 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2005-0133 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 31 2005 12:00AM |
| Updated: | Jul 12 2009 10:06AM |
| Credit: | The individual or individuals responsible for the discovery of this issue are currently unknown; the vendor disclosed this issue. |
| Vulnerable: |
Trustix Secure Linux 2.2 Trustix Secure Linux 2.1 Trustix Secure Linux 1.5 Trustix Secure Enterprise Linux 2.0 SuSE Linux 8.1 SuSE Linux 8.0 i386 SuSE Linux 8.0 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Clam Anti-Virus ClamAV 0.80 rc4 Clam Anti-Virus ClamAV 0.80 rc3 Clam Anti-Virus ClamAV 0.80 rc2 Clam Anti-Virus ClamAV 0.80 rc1 Clam Anti-Virus ClamAV 0.80 Clam Anti-Virus ClamAV 0.70 Clam Anti-Virus ClamAV 0.68 -1 Clam Anti-Virus ClamAV 0.68 Clam Anti-Virus ClamAV 0.67 Clam Anti-Virus ClamAV 0.65 Clam Anti-Virus ClamAV 0.60 Clam Anti-Virus ClamAV 0.54 Clam Anti-Virus ClamAV 0.53 Clam Anti-Virus ClamAV 0.52 Clam Anti-Virus ClamAV 0.51 ALT Linux ALT Linux Junior 2.3 ALT Linux ALT Linux Compact 2.3 |
| Not Vulnerable: |
Clam Anti-Virus ClamAV 0.81 |
Discussion
Clam Anti-Virus ClamAV ZIP File Parsing Remote Denial Of Service Vulnerability
A remote denial of service vulnerability affects ClamAV. This issue is due to a failure of the application to properly handle malicious file content.
An attacker may leverage this issue to crash the Clam Anti-Virus daemon, potentially leaving an affected computer open to infection by malicious code.
A remote denial of service vulnerability affects ClamAV. This issue is due to a failure of the application to properly handle malicious file content.
An attacker may leverage this issue to crash the Clam Anti-Virus daemon, potentially leaving an affected computer open to infection by malicious code.
Exploit / POC
Clam Anti-Virus ClamAV ZIP File Parsing Remote Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Clam Anti-Virus ClamAV ZIP File Parsing Remote Denial Of Service Vulnerability
Solution:
The vendor has released an upgrade dealing with this issue.
Conectiva has released advisory CLA-2005:928 to address this issue. Please see the attached advisory for further information on obtaining and applying fixes.
Gentoo linux has made advisory GLSA 200501-46 dealing with this issue. Gentoo advises that all ClamAV users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-antivirus/clamav-0.81"
For more information, please see the referenced Gentoo linux advisory.
Mandrake has released advisory MDKSA-2005:025 to address this issue. Please see the referenced advisory for more information.
SuSE Linux has released a security summary report (SUSE-SR:2005:003) that contains fixes to address this and other vulnerabilities. Customers are advised to peruse the referenced advisory for further information regarding obtaining and applying appropriate updates.
Trustix has released advisory TSLSA-2005-0003 to address various issues in multiple products. Please see the referenced advisory for more information.
ALT Linux has released updates dealing with this and other issues. Please see the reference section for more information.
Clam Anti-Virus ClamAV 0.51
Clam Anti-Virus ClamAV 0.52
Clam Anti-Virus ClamAV 0.53
Clam Anti-Virus ClamAV 0.54
Clam Anti-Virus ClamAV 0.60
Clam Anti-Virus ClamAV 0.65
Clam Anti-Virus ClamAV 0.67
Clam Anti-Virus ClamAV 0.68
Clam Anti-Virus ClamAV 0.68 -1
Clam Anti-Virus ClamAV 0.70
Clam Anti-Virus ClamAV 0.80 rc4
Clam Anti-Virus ClamAV 0.80
Clam Anti-Virus ClamAV 0.80 rc3
Clam Anti-Virus ClamAV 0.80 rc1
Clam Anti-Virus ClamAV 0.80 rc2
Solution:
The vendor has released an upgrade dealing with this issue.
Conectiva has released advisory CLA-2005:928 to address this issue. Please see the attached advisory for further information on obtaining and applying fixes.
Gentoo linux has made advisory GLSA 200501-46 dealing with this issue. Gentoo advises that all ClamAV users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-antivirus/clamav-0.81"
For more information, please see the referenced Gentoo linux advisory.
Mandrake has released advisory MDKSA-2005:025 to address this issue. Please see the referenced advisory for more information.
SuSE Linux has released a security summary report (SUSE-SR:2005:003) that contains fixes to address this and other vulnerabilities. Customers are advised to peruse the referenced advisory for further information regarding obtaining and applying appropriate updates.
Trustix has released advisory TSLSA-2005-0003 to address various issues in multiple products. Please see the referenced advisory for more information.
ALT Linux has released updates dealing with this and other issues. Please see the reference section for more information.
Clam Anti-Virus ClamAV 0.51
-
Clam Anti-Virus ClamAV 0.81
http://sourceforge.net/project/showfiles.php?group_id=86638&release_id =300116
Clam Anti-Virus ClamAV 0.52
-
Clam Anti-Virus ClamAV 0.81
http://sourceforge.net/project/showfiles.php?group_id=86638&release_id =300116
Clam Anti-Virus ClamAV 0.53
-
Clam Anti-Virus ClamAV 0.81
http://sourceforge.net/project/showfiles.php?group_id=86638&release_id =300116
Clam Anti-Virus ClamAV 0.54
-
Clam Anti-Virus ClamAV 0.81
http://sourceforge.net/project/showfiles.php?group_id=86638&release_id =300116
Clam Anti-Virus ClamAV 0.60
-
Clam Anti-Virus ClamAV 0.81
http://sourceforge.net/project/showfiles.php?group_id=86638&release_id =300116
Clam Anti-Virus ClamAV 0.65
-
Clam Anti-Virus ClamAV 0.81
http://sourceforge.net/project/showfiles.php?group_id=86638&release_id =300116
Clam Anti-Virus ClamAV 0.67
-
Clam Anti-Virus ClamAV 0.81
http://sourceforge.net/project/showfiles.php?group_id=86638&release_id =300116 -
SuSE clamav-0.80-2.5.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/clamav-0.80-2.5.i 586.rpm -
SuSE clamav-0.80-2.5.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/clamav-0.80-2 .5.x86_64.rpm
Clam Anti-Virus ClamAV 0.68
-
Clam Anti-Virus ClamAV 0.81
http://sourceforge.net/project/showfiles.php?group_id=86638&release_id =300116
Clam Anti-Virus ClamAV 0.68 -1
-
Clam Anti-Virus ClamAV 0.81
http://sourceforge.net/project/showfiles.php?group_id=86638&release_id =300116
Clam Anti-Virus ClamAV 0.70
-
Clam Anti-Virus ClamAV 0.81
http://sourceforge.net/project/showfiles.php?group_id=86638&release_id =300116 -
Mandrake clamav-0.81-0.2.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake clamav-0.81-0.2.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake clamav-0.81-0.2.C30mdk.i586.rpm
Mandrake Corporate Server 3.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake clamav-0.81-0.2.C30mdk.x86_64.rpm
Mandrake Corporate Server 3.0/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake clamav-db-0.81-0.2.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake clamav-db-0.81-0.2.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake clamav-db-0.81-0.2.C30mdk.i586.rpm
Mandrake Corporate Server 3.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake clamav-db-0.81-0.2.C30mdk.x86_64.rpm
Mandrake Corporate Server 3.0/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake clamav-milter-0.81-0.2.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake clamav-milter-0.81-0.2.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake clamav-milter-0.81-0.2.C30mdk.i586.rpm
Mandrake Corporate Server 3.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake clamav-milter-0.81-0.2.C30mdk.x86_64.rpm
Mandrake Corporate Server 3.0/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lib64clamav1-0.81-0.2.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lib64clamav1-0.81-0.2.C30mdk.x86_64.rpm
Mandrake Corporate Server 3.0/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lib64clamav1-devel-0.81-0.2.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lib64clamav1-devel-0.81-0.2.C30mdk.x86_64.rpm
Mandrake Corporate Server 3.0/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libclamav1-0.81-0.2.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libclamav1-0.81-0.2.C30mdk.i586.rpm
Mandrake Corporate Server 3.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libclamav1-devel-0.81-0.2.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libclamav1-devel-0.81-0.2.C30mdk.i586.rpm
Mandrake Corporate Server 3.0
http://www.mandrakesecure.net/en/ftp.php
Clam Anti-Virus ClamAV 0.80 rc4
-
Clam Anti-Virus ClamAV 0.81
http://sourceforge.net/project/showfiles.php?group_id=86638&release_id =300116
Clam Anti-Virus ClamAV 0.80
-
Clam Anti-Virus ClamAV 0.81
http://sourceforge.net/project/showfiles.php?group_id=86638&release_id =300116 -
Trustix clamav-0.80-3tr.i586.rpm
Trustix Secure Linux 2.2
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix clamav-devel-0.80-3tr.i586.rpm
Trustix Secure Linux 2.2
ftp://ftp.trustix.org/pub/trustix/updates/
Clam Anti-Virus ClamAV 0.80 rc3
-
Clam Anti-Virus ClamAV 0.81
http://sourceforge.net/project/showfiles.php?group_id=86638&release_id =300116 -
Conectiva clamav-0.83-70136U10_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/clamav-0.83-70136U10_7cl.i 386.rpm -
Conectiva clamav-database-0.83.20041125-70136U10_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/clamav-database-0.83.20041 125-70136U10_7cl.i386.rpm -
Conectiva libclamav-devel-0.83-70136U10_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libclamav-devel-0.83-70136 U10_7cl.i386.rpm -
Conectiva libclamav-devel-static-0.83-70136U10_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libclamav-devel-static-0.8 3-70136U10_7cl.i386.rpm -
Conectiva libclamav1-0.83-70136U10_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libclamav1-0.83-70136U10_7 cl.i386.rpm -
SuSE clamav-0.80-2.3.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/clamav-0.80-2.3.i 586.rpm -
SuSE clamav-0.80-2.3.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/x86_64/clamav-0.80-2 .3.x86_64.rpm
Clam Anti-Virus ClamAV 0.80 rc1
-
Clam Anti-Virus ClamAV 0.81
http://sourceforge.net/project/showfiles.php?group_id=86638&release_id =300116
Clam Anti-Virus ClamAV 0.80 rc2
-
Clam Anti-Virus ClamAV 0.81
http://sourceforge.net/project/showfiles.php?group_id=86638&release_id =300116
References
Clam Anti-Virus ClamAV ZIP File Parsing Remote Denial Of Service Vulnerability
References:
References:
- [security-announce] I: updated packages available (ALT Linux)
- ClamAV Homepage (Clam Anti-Virus)
- ClamAV Version 0.81 Change Log (Clam Anti-Virus)