Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.900545
Kategorie:Denial of Service
Titel:ClamAV < 0.95.1 Multiple DoS Vulnerabilities - Linux
Zusammenfassung:ClamAV is prone to multiple denial of service (DoS); vulnerabilities.
Beschreibung:Summary:
ClamAV is prone to multiple denial of service (DoS)
vulnerabilities.

Vulnerability Insight:
- Error in CLI_ISCONTAINED macro in libclamav/others.h while
processing malformed files packed with UPack.

- Buffer overflow error in cli_url_canon() function in libclamav/phishcheck.c while handling
specially crafted URLs.

Vulnerability Impact:
Attackers can exploit this issue by executing arbitrary code via
a crafted URL in the context of affected application, and can cause denial of service.

Affected Software/OS:
ClamAV before version 0.95.1.

Solution:
Update to version 0.95.1 or later.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-1371
http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html
BugTraq ID: 34446
http://www.securityfocus.com/bid/34446
Debian Security Information: DSA-1771 (Google Search)
http://www.debian.org/security/2009/dsa-1771
http://www.mandriva.com/security/advisories?name=MDVSA-2009:097
http://osvdb.org/53602
http://www.securitytracker.com/id?1022028
http://secunia.com/advisories/34612
http://secunia.com/advisories/34654
http://secunia.com/advisories/34716
http://secunia.com/advisories/36701
http://www.ubuntu.com/usn/usn-756-1
http://www.vupen.com/english/advisories/2009/0985
Common Vulnerability Exposure (CVE) ID: CVE-2009-1372
http://osvdb.org/53603
CopyrightCopyright (C) 2009 Greenbone Networks GmbH

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.