Clam AntiVirus E-mail Address Logging Format String Vulnerability
BID:9031
Info
Clam AntiVirus E-mail Address Logging Format String Vulnerability
| Bugtraq ID: | 9031 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 12 2003 12:00AM |
| Updated: | Nov 12 2003 12:00AM |
| Credit: | Discovery is credited to Secure Network Operations. |
| Vulnerable: |
Tomasz Kojm Clam AntiVirus 0.60 p Tomasz Kojm Clam AntiVirus 0.60 |
| Not Vulnerable: |
Tomasz Kojm Clam AntiVirus 0.65 Tomasz Kojm Clam AntiVirus 0.60 q |
Discussion
Clam AntiVirus E-mail Address Logging Format String Vulnerability
Clam AntiVirus is prone to a format string vulnerability when logging e-mail addresses. This may be exploited to overwrite arbitrary locations in memory with attacker-supplied values, resulting in execution of arbitrary code.
This issue only affects the clamav-milter component of versions later than clamav-0.54, which include syslogging functionality.
Clam AntiVirus is prone to a format string vulnerability when logging e-mail addresses. This may be exploited to overwrite arbitrary locations in memory with attacker-supplied values, resulting in execution of arbitrary code.
This issue only affects the clamav-milter component of versions later than clamav-0.54, which include syslogging functionality.
Exploit / POC
Clam AntiVirus E-mail Address Logging Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Clam AntiVirus E-mail Address Logging Format String Vulnerability
Solution:
This issue has been addressed as of clamav-0.60q. Users should upgrade to the most recent version.
Tomasz Kojm Clam AntiVirus 0.60 p
Tomasz Kojm Clam AntiVirus 0.60
Solution:
This issue has been addressed as of clamav-0.60q. Users should upgrade to the most recent version.
Tomasz Kojm Clam AntiVirus 0.60 p
-
Tomasz Kojm clamav-0.65.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.65.tar.gz
Tomasz Kojm Clam AntiVirus 0.60
-
Tomasz Kojm clamav-0.65.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.65.tar.gz
References
Clam AntiVirus E-mail Address Logging Format String Vulnerability
References:
References:
- Clam AntiVirus Home Page (Tomasz Kojm)
- SRT2003-11-11-1151 - clamav-milter remote exploit / DoS (KF
)