FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-0162

This CVE name corresponds to:

Entered Topic
2006-01-10 clamav -- possible heap overflow in the UPX code

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-0162
Phase Assigned(20060110)

Description

Heap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV) before 0.88 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted UPX files.

References

Source Reference
FULLDISC 20060112 ZDI-06-001: Clam AntiVirus UPX Unpacking Code Execution Vulnerability
MISC http://www.zerodayinitiative.com/advisories/ZDI-06-001.html
CONFIRM http://www.clamav.net/doc/0.88/ChangeLog
DEBIAN DSA-947
GENTOO GLSA-200601-07
MANDRIVA MDKSA-2006:016
TRUSTIX 2006-0002
CERT-VN VU#385908
BID 16191
VUPEN ADV-2006-0116
OSVDB 22318
SECTRACK 1015457
SECUNIA 18379
SECUNIA 18453
SECUNIA 18478
SECUNIA 18548
SECUNIA 18463
SREASON 342
XF clamav-libclamav-upx-bo(24047)