<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Wazi &#187; clamav</title>
	<atom:link href="http://olex.openlogic.com/wazi/tag/clamav/feed/" rel="self" type="application/rss+xml" />
	<link>http://olex.openlogic.com/wazi</link>
	<description>Thinking OPEN</description>
	<lastBuildDate>Fri, 06 Nov 2009 19:33:28 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Clamav 0.93.3 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2009/clamav-0933-and-prior-medium-2/</link>
		<comments>http://olex.openlogic.com/wazi/2009/clamav-0933-and-prior-medium-2/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/clamav-0933-and-prior-medium-2/</guid>
		<description><![CDATA[The unpack feature in ClamAV 0.93.3 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a corrupted LZH file....

CVE Identifier: CVE-2008-6845
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 0.93.3 and prior [Medium]
</ul>
<h3>Description</h3>
<p>The unpack feature in ClamAV 0.93.3 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a corrupted LZH file.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6845" target="_blank">CVE-2008-6845</a><br />
Severity: Medium
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/clamav-0933-and-prior-medium-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clamav 0.95 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2009/clamav-095-and-prior-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2009/clamav-095-and-prior-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/clamav-095-and-prior-medium/</guid>
		<description><![CDATA[The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding....

CVE Identifier: CVE-2009-1371
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 0.95 and prior [Medium]
</ul>
<h3>Description</h3>
<p>The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1371" target="_blank">CVE-2009-1371</a><br />
Severity: Medium
</p>
<p></p>
<div style="align:right;"><div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div></p>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/clamav-095-and-prior-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clamav 0.95 and prior [Unknown Severity]</title>
		<link>http://olex.openlogic.com/wazi/2009/clamav-095-and-prior-unknown-severity/</link>
		<comments>http://olex.openlogic.com/wazi/2009/clamav-095-and-prior-unknown-severity/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/clamav-095-and-prior-unknown-severity/</guid>
		<description><![CDATA[Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL....

CVE Identifier: CVE-2009-1372
Vulnerability Type(s): 
Severity: Unknown Severity
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 0.95 and prior [Unknown Severity]
</ul>
<h3>Description</h3>
<p>Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1372" target="_blank">CVE-2009-1372</a><br />
Severity: Unknown Severity
</p>
<p></p>
<div style="align:right;"><div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div></p>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/clamav-095-and-prior-unknown-severity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clamav 0.94.1 and prior [High]</title>
		<link>http://olex.openlogic.com/wazi/2009/clamav-0941-and-prior-high/</link>
		<comments>http://olex.openlogic.com/wazi/2009/clamav-0941-and-prior-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/clamav-0941-and-prior-high/</guid>
		<description><![CDATA[libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang....

CVE Identifier: CVE-2009-1270
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 0.94.1 and prior [High]
</ul>
<h3>Description</h3>
<p>libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1270" target="_blank">CVE-2009-1270</a><br />
Severity: High
</p>
<p></p>
<div style="align:right;"><div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div></p>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/clamav-0941-and-prior-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clamav 0.94.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2009/clamav-0942-and-prior-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2009/clamav-0942-and-prior-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/clamav-0942-and-prior-medium/</guid>
		<description><![CDATA[libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error....

CVE Identifier: CVE-2008-6680
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 0.94.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6680" target="_blank">CVE-2008-6680</a><br />
Severity: Medium
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/clamav-0942-and-prior-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clamav 0.91rc2 and prior [High]</title>
		<link>http://olex.openlogic.com/wazi/2009/clamav-091rc2-and-prior-high/</link>
		<comments>http://olex.openlogic.com/wazi/2009/clamav-091rc2-and-prior-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/clamav-091rc2-and-prior-high/</guid>
		<description><![CDATA[Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive....

CVE Identifier: CVE-2009-1241
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 0.91rc2 and prior [High]
</ul>
<h3>Description</h3>
<p>Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1241" target="_blank">CVE-2009-1241</a><br />
Severity: High
</p>
<p></p>
<div style="align:right;"><div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div></p>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/clamav-091rc2-and-prior-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clamav 7 and prior [High]</title>
		<link>http://olex.openlogic.com/wazi/2008/clamav-7-and-prior-high/</link>
		<comments>http://olex.openlogic.com/wazi/2008/clamav-7-and-prior-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2008/clamav-7-and-prior-high/</guid>
		<description><![CDATA[ClamAV 0.94.1 and possibly 0.93.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit....

CVE Identifier: CVE-2008-5525
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 7 and prior [High]
</ul>
<h3>Description</h3>
<p>ClamAV 0.94.1 and possibly 0.93.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka &#8220;EXE info&#8221;) at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5525" target="_blank">CVE-2008-5525</a><br />
Severity: High
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2008/clamav-7-and-prior-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clamav 0.94.1 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2008/clamav-0941-and-prior-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2008/clamav-0941-and-prior-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2008/clamav-0941-and-prior-medium/</guid>
		<description><![CDATA[Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted JPEG file, related to the cli_check_jpeg_exploit, jpeg_check_photoshop, and jpeg_check_photoshop_8bim functions....

CVE Identifier: CVE-2008-5314
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 0.94.1 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted JPEG file, related to the cli_check_jpeg_exploit, jpeg_check_photoshop, and jpeg_check_photoshop_8bim functions.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5314" target="_blank">CVE-2008-5314</a><br />
Severity: Medium
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2008/clamav-0941-and-prior-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clamav 0.91rc2 and prior [High]</title>
		<link>http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-high-2/</link>
		<comments>http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-high-2/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-high-2/</guid>
		<description><![CDATA[Off-by-one error in the get_unicode_name function (libclamav/vba_extract.c) in Clam Anti-Virus (ClamAV) before 0.94.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted VBA project file, which triggers a heap-based buffer overflow....

CVE Identifier: CVE-2008-5050
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 0.91rc2 and prior [High]
</ul>
<h3>Description</h3>
<p>Off-by-one error in the get_unicode_name function (libclamav/vba_extract.c) in Clam Anti-Virus (ClamAV) before 0.94.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted VBA project file, which triggers a heap-based buffer overflow.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5050" target="_blank">CVE-2008-5050</a><br />
Severity: High
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-high-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clamav 0.91rc2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-medium-3/</link>
		<comments>http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-medium-3/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-medium-3/</guid>
		<description><![CDATA[libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an out-of-memory condition....

CVE Identifier: CVE-2008-3912
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 0.91rc2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an out-of-memory condition.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3912" target="_blank">CVE-2008-3912</a><br />
Severity: Medium
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-medium-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clamav 0.91rc2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-medium-4/</link>
		<comments>http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-medium-4/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-medium-4/</guid>
		<description><![CDATA[Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic"....

CVE Identifier: CVE-2008-3913
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 0.91rc2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to &#8220;error handling logic&#8221;.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3913" target="_blank">CVE-2008-3913</a><br />
Severity: Medium
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-medium-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clamav 0.91rc2 and prior [Unknown Severity]</title>
		<link>http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-unknown-severity/</link>
		<comments>http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-unknown-severity/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-unknown-severity/</guid>
		<description><![CDATA[Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c....

CVE Identifier: CVE-2008-3914
Vulnerability Type(s): 
Severity: Unknown Severity
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 0.91rc2 and prior [Unknown Severity]
</ul>
<h3>Description</h3>
<p>Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the &#8220;error path&#8221; in (1) libclamav/others.c and (2) libclamav/sis.c.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3914" target="_blank">CVE-2008-3914</a><br />
Severity: Unknown Severity
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-unknown-severity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clamav 0.93.3 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2008/clamav-0933-and-prior-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2008/clamav-0933-and-prior-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2008/clamav-0933-and-prior-medium/</guid>
		<description><![CDATA[libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote attackers to cause a denial of service (application crash) via a malformed CHM file, related to an "invalid memory access."...

CVE Identifier: CVE-2008-1389
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 0.93.3 and prior [Medium]
</ul>
<h3>Description</h3>
<p>libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote attackers to cause a denial of service (application crash) via a malformed CHM file, related to an &#8220;invalid memory access.&#8221;</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1389" target="_blank">CVE-2008-1389</a><br />
Severity: Medium
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2008/clamav-0933-and-prior-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clamav 0.93 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2008/clamav-093-and-prior-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2008/clamav-093-and-prior-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2008/clamav-093-and-prior-medium/</guid>
		<description><![CDATA[libclamav/petite.c in ClamAV before 0.93.3 allows remote attackers to cause a denial of service via a malformed Petite file that triggers an out-of-bounds memory access...

CVE Identifier: CVE-2008-3215
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 0.93 and prior [Medium]
</ul>
<h3>Description</h3>
<p>libclamav/petite.c in ClamAV before 0.93.3 allows remote attackers to cause a denial of service via a malformed Petite file that triggers an out-of-bounds memory access.  NOTE: this issue exists because of an incomplete fix for CVE-2008-2713.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3215" target="_blank">CVE-2008-3215</a><br />
Severity: Medium
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2008/clamav-093-and-prior-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clamav 0.90_rc3 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2008/clamav-090_rc3-and-prior-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2008/clamav-090_rc3-and-prior-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2008/clamav-090_rc3-and-prior-medium/</guid>
		<description><![CDATA[libclamav/petite.c in ClamAV before 0.93.1 allows remote attackers to cause a denial of service via a crafted Petite file that triggers an out-of-bounds read....

CVE Identifier: CVE-2008-2713
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 0.90_rc3 and prior [Medium]
</ul>
<h3>Description</h3>
<p>libclamav/petite.c in ClamAV before 0.93.1 allows remote attackers to cause a denial of service via a crafted Petite file that triggers an out-of-bounds read.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2713" target="_blank">CVE-2008-2713</a><br />
Severity: Medium
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2008/clamav-090_rc3-and-prior-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clamav 0.90rc1 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2008/clamav-090rc1-and-prior-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2008/clamav-090rc1-and-prior-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2008/clamav-090rc1-and-prior-medium/</guid>
		<description><![CDATA[ClamAV before 0.93 allows remote attackers to cause a denial of service (CPU consumption) via a crafted ARJ archive, as demonstrated by the PROTOS GENOME test suite for Archive Formats....

CVE Identifier: CVE-2008-1387
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 0.90rc1 and prior [Medium]
</ul>
<h3>Description</h3>
<p>ClamAV before 0.93 allows remote attackers to cause a denial of service (CPU consumption) via a crafted ARJ archive, as demonstrated by the PROTOS GENOME test suite for Archive Formats.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1387" target="_blank">CVE-2008-1387</a><br />
Severity: Medium
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2008/clamav-090rc1-and-prior-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clamav 0.91rc2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-medium/</guid>
		<description><![CDATA[ClamAV before 0.93 allows remote attackers to bypass the scanning enging via a RAR file with an invalid version number, which cannot be parsed by ClamAV but can be extracted by Winrar....

CVE Identifier: CVE-2008-1835
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 0.91rc2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>ClamAV before 0.93 allows remote attackers to bypass the scanning enging via a RAR file with an invalid version number, which cannot be parsed by ClamAV but can be extracted by Winrar.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1835" target="_blank">CVE-2008-1835</a><br />
Severity: Medium
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clamav 0.90rc1 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2008/clamav-090rc1-and-prior-medium-2/</link>
		<comments>http://olex.openlogic.com/wazi/2008/clamav-090rc1-and-prior-medium-2/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2008/clamav-090rc1-and-prior-medium-2/</guid>
		<description><![CDATA[The rfc2231 function in message.c in libclamav in ClamAV before 0.93 allows remote attackers to cause a denial of service (crash) via a crafted message that produces a string that is not null terminated, which triggers a buffer over-read....

CVE Identifier: CVE-2008-1836
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 0.90rc1 and prior [Medium]
</ul>
<h3>Description</h3>
<p>The rfc2231 function in message.c in libclamav in ClamAV before 0.93 allows remote attackers to cause a denial of service (crash) via a crafted message that produces a string that is not null terminated, which triggers a buffer over-read.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1836" target="_blank">CVE-2008-1836</a><br />
Severity: Medium
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2008/clamav-090rc1-and-prior-medium-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clamav 0.91rc2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-medium-2/</link>
		<comments>http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-medium-2/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-medium-2/</guid>
		<description><![CDATA[libclamunrar in ClamAV before 0.93 allows remote attackers to cause a denial of service (crash) via crafted RAR files that trigger "memory problems," as demonstrated by the PROTOS GENOME test suite for Archive Formats....

CVE Identifier: CVE-2008-1837
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 0.91rc2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>libclamunrar in ClamAV before 0.93 allows remote attackers to cause a denial of service (crash) via crafted RAR files that trigger &#8220;memory problems,&#8221; as demonstrated by the PROTOS GENOME test suite for Archive Formats.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1837" target="_blank">CVE-2008-1837</a><br />
Severity: Medium
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2008/clamav-091rc2-and-prior-medium-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clamav 0.92.1 [High]</title>
		<link>http://olex.openlogic.com/wazi/2008/clamav-0921-high/</link>
		<comments>http://olex.openlogic.com/wazi/2008/clamav-0921-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[clamav]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2008/clamav-0921-high/</guid>
		<description><![CDATA[Heap-based buffer overflow in spin.c in libclamav in ClamAV 0.92.1 allows remote attackers to execute arbitrary code via a crafted PeSpin packed PE binary with a modified length value....

CVE Identifier: CVE-2008-0314
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Clamav 0.92.1 [High]
</ul>
<h3>Description</h3>
<p>Heap-based buffer overflow in spin.c in libclamav in ClamAV 0.92.1 allows remote attackers to execute arbitrary code via a crafted PeSpin packed PE binary with a modified length value.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0314" target="_blank">CVE-2008-0314</a><br />
Severity: High
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2008/clamav-0921-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
