Clamav 0.95 and prior [Unknown Severity]

By Security Team on Thursday, April 23rd, 2009 in Security Notifications | Related Software Packages:

Affects:

  • Clamav 0.95 and prior [Unknown Severity]

Description

Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL.

If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.

CVE Identifier: CVE-2009-1372
Severity: Unknown Severity

National Vulnerabilities Database

NIST National Vulnerabilities Database

Security Team

We'll keep you safe. Trust us, that's our job. Even though, contrary to what our Avatar might imply, we're not all linebackers. In fact, some of us are quite petite. And others of us wear high heeled boots. Red. Wondering whether we also know what we're talking about? C'mon -have you read any of these security posts?

Comments are closed.