FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-1614

This CVE name corresponds to:

Entered Topic
2006-04-06 clamav -- Multiple Vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-1614
Phase Assigned(20060405)

Description

Integer overflow in the cli_scanpe function in the PE header parser (libclamav/pe.c) in Clam AntiVirus (ClamAV) before 0.88.1, when ArchiveMaxFileSize is disabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code.

References

Source Reference
BUGTRAQ 20060406 [Overflow.pl] Clam AntiVirus Win32-UPX Heap Overflow (not default configuration)
MISC http://www.overflow.pl/adv/clamavupxinteger.txt
CONFIRM http://sourceforge.net/project/shownotes.php?release_id=407078&group_id=86638
CONFIRM http://up2date.astaro.com/2006/05/low_up2date_6202.html
APPLE APPLE-SA-2006-05-11
DEBIAN DSA-1024
GENTOO GLSA-200604-06
MANDRIVA MDKSA-2006:067
SUSE SUSE-SA:2006:020
TRUSTIX 2006-0020
CERT TA06-132A
BID 17388
BID 17951
VUPEN ADV-2006-1258
VUPEN ADV-2006-1779
OSVDB 24457
SECTRACK 1015887
SECUNIA 19534
SECUNIA 19536
SECUNIA 19570
SECUNIA 19608
SECUNIA 19564
SECUNIA 19567
SECUNIA 20077
SECUNIA 23719
XF clamav-pe-overflow(25660)