FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-1387

This CVE name corresponds to:

Entered Topic
2008-04-15 clamav -- Multiple Vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-1387
Phase Assigned(20080318)

Description

ClamAV before 0.93 allows remote attackers to cause a denial of service (CPU consumption) via a crafted ARJ archive, as demonstrated by the PROTOS GENOME test suite for Archive Formats.

References

Source Reference
BUGTRAQ 20080415 clamav: Endless loop / hang with crafter arj, CVE-2008-1387
MISC http://int21.de/cve/CVE-2008-1387-clamav.html
MISC http://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html
MISC http://www.ee.oulu.fi/research/ouspg/protos/testing/c10/archive/
CONFIRM https://www.clamav.net/bugzilla/show_bug.cgi?id=897
CONFIRM http://kolab.org/security/kolab-vendor-notice-20.txt
FEDORA FEDORA-2008-3358
FEDORA FEDORA-2008-3420
FEDORA FEDORA-2008-3900
MANDRIVA MDVSA-2008:088
SUSE SUSE-SA:2008:024
BID 28784
FRSIRT ADV-2008-1227
SECUNIA 29863
SECUNIA 29891
SECUNIA 29975
SECUNIA 30253
SECUNIA 30328
XF clamav-arj-unspecified-dos(41822)