Lucene search

K
osvGoogleOSV:DSA-1366-1
HistorySep 01, 2007 - 12:00 a.m.

clamav

2007-09-0100:00:00
Google
osv.dev
11

EPSS

0.966

Percentile

99.7%

Several remote vulnerabilities have been discovered in the Clam anti-virus
toolkit. The Common Vulnerabilities and Exposures project identifies the
following problems:

  • CVE-2007-4510
    It was discovered that the RTF and RFC2397 parsers can be tricked
    into dereferencing a NULL pointer, resulting in denial of service.
  • CVE-2007-4560
    It was discovered that clamav-milter performs insufficient input
    sanitising, resulting in the execution of arbitrary shell commands.

The oldstable distribution (sarge) is only affected by a subset of
the problems. An update will be provided later.

For the stable distribution (etch) these problems have been fixed
in version 0.90.1-3etch7.

For the unstable distribution (sid) these problems have been fixed in
version 0.91.2-1.

We recommend that you upgrade your clamav packages.