Executive Summary
Summary | |
---|---|
Title | New ClamAV packages fix denial of service |
Informations | |||
---|---|---|---|
Name | DSA-1340 | First vendor Publication | 2007-07-24 |
Vendor | Debian | Last vendor Modification | 2007-07-24 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:N/I:N/A:P) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
A NULL pointer dereference has been discovered in the RAR VM of Clam Antivirus (ClamAV) which allows user-assisted remote attackers to cause a denial of service via a specially crafted RAR archives. We are currently unable to provide fixed packages for the MIPS architectures. Those packages will be installed in the security archive when they become available. The old stable distribution (sarge) is not affected by this problem. For the stable distribution (etch) this problem has been fixed in version 0.90.1-3etch4. For the unstable distribution (sid) this problem has been fixed in version 0.91-1. We recommend that you upgrade your clamav packages. |
Original Source
Url : http://www.debian.org/security/2007/dsa-1340 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:18711 | |||
Oval ID: | oval:org.mitre.oval:def:18711 | ||
Title: | DSA-1340-1 clamav - null pointer dereference | ||
Description: | A NULL pointer dereference has been discovered in the RAR VM of Clam Antivirus (ClamAV) which allows user-assisted remote attackers to cause a denial of service via a specially crafted RAR archives. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1340-1 CVE-2007-3725 | Version: | 7 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | clamav |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2009-10-10 | Name : SLES9: Security update for clamav File : nvt/sles9p5012460.nasl |
2009-04-09 | Name : Mandriva Update for clamav MDKSA-2007:150 (clamav) File : nvt/gb_mandriva_MDKSA_2007_150.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200708-04 (clamav) File : nvt/glsa_200708_04.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 1340-1 (clamav) File : nvt/deb_1340_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
36907 | Clam AntiVirus RAR Archive Processing DoS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2008-03-19 | Name : The remote host is missing a Mac OS X update that fixes various security issues. File : macosx_SecUpd2008-002.nasl - Type : ACT_GATHER_INFO |
2007-12-13 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_clamav-3902.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_clamav-3901.nasl - Type : ACT_GATHER_INFO |
2007-08-13 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200708-04.nasl - Type : ACT_GATHER_INFO |
2007-07-27 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1340.nasl - Type : ACT_GATHER_INFO |
2007-07-27 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2007-150.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:26:46 |
|