clamav vulnerability

Related Vulnerabilities: CVE-2011-2721  

An attacker could send crafted input to ClamAV and cause it to crash.

It was discovered that the hash processing code in libclamav improperly handled messages with certain hashes. This could allow a remote attacker to craft a document that could cause clamav to crash, resulting in a denial of service.

28 July 2011

clamav vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 11.04

Summary

An attacker could send crafted input to ClamAV and cause it to crash.

Software Description

  • clamav - anti-virus utility for Unix - command-line interface

Details

It was discovered that the hash processing code in libclamav improperly handled messages with certain hashes. This could allow a remote attacker to craft a document that could cause clamav to crash, resulting in a denial of service.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 11.04
libclamav6 - 0.97+dfsg-2ubuntu1.1

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References