FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-1387

This CVE name corresponds to:

Entered Topic
2008-04-15 clamav -- Multiple Vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-1387
Phase Assigned(20080318)

Description

ClamAV before 0.93 allows remote attackers to cause a denial of service (CPU consumption) via a crafted ARJ archive, as demonstrated by the PROTOS GENOME test suite for Archive Formats.

References

Source Reference
BUGTRAQ 20080415 clamav: Endless loop / hang with crafter arj, CVE-2008-1387
MISC http://int21.de/cve/CVE-2008-1387-clamav.html
MISC http://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html
MISC http://www.ee.oulu.fi/research/ouspg/protos/testing/c10/archive/
CONFIRM https://www.clamav.net/bugzilla/show_bug.cgi?id=897
CONFIRM http://kolab.org/security/kolab-vendor-notice-20.txt
CONFIRM http://up2date.astaro.com/2008/08/up2date_asg_v7300_ga_released.html
APPLE APPLE-SA-2008-09-15
FEDORA FEDORA-2008-3358
FEDORA FEDORA-2008-3420
FEDORA FEDORA-2008-3900
GENTOO GLSA-200805-19
MANDRIVA MDVSA-2008:088
SUSE SUSE-SA:2008:024
CERT TA08-260A
BID 28784
BID 28782
VUPEN ADV-2008-1227
VUPEN ADV-2008-2584
SECUNIA 29863
SECUNIA 29891
SECUNIA 29975
SECUNIA 30253
SECUNIA 30328
SECUNIA 31576
SECUNIA 31882
XF clamav-arj-unspecified-dos(41822)