Executive Summary
Summary | |
---|---|
Title | ClamAV vulnerabilities |
Informations | |||
---|---|---|---|
Name | USN-926-1 | First vendor Publication | 2010-04-08 |
Vendor | Ubuntu | Last vendor Modification | 2010-04-08 |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
A security issue affects the following Ubuntu releases: Ubuntu 8.10 Ubuntu 9.04 Ubuntu 9.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.10: Ubuntu 9.04: Ubuntu 9.10: In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: It was discovered that ClamAV did not properly verify its input when processing CAB files. A remote attacker could send a specially crafted CAB file to evade malware detection. (CVE-2010-0098) It was discovered that ClamAV did not properly verify its input when processing CAB files. A remote attacker could send a specially crafted CAB file and cause a denial of service via application crash. |
Original Source
Url : http://www.ubuntu.com/usn/USN-926-1 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-20 | Improper Input Validation |
OVAL Definitions
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2011-03-09 | Name : Gentoo Security Advisory GLSA 201009-06 (clamav) File : nvt/glsa_201009_06.nasl |
2010-05-28 | Name : Mandriva Update for clamav MDVSA-2010:082-1 (clamav) File : nvt/gb_mandriva_MDVSA_2010_082_1.nasl |
2010-04-19 | Name : Mandriva Update for clamav MDVSA-2010:082 (clamav) File : nvt/gb_mandriva_MDVSA_2010_082.nasl |
2010-04-13 | Name : ClamAV Security Bypass And Memory Corruption Vulnerabilities (Win) File : nvt/gb_clamav_sec_bypass_n_mem_corr_vuln_win.nasl |
2010-04-09 | Name : Ubuntu Update for clamav vulnerabilities USN-926-1 File : nvt/gb_ubuntu_USN_926_1.nasl |
2010-03-02 | Name : Mandriva Update for drakxtools MDVA-2010:082 (drakxtools) File : nvt/gb_mandriva_MDVA_2010_082.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
63861 | ClamAV Malformed CAB File Scanning Bypass |
63818 | ClamAV libclamav/mspack.c qtm_decompress Function Crafted CAB Archive DoS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-12-02 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_clamav-100414.nasl - Type : ACT_GATHER_INFO |
2010-10-11 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_clamav-6990.nasl - Type : ACT_GATHER_INFO |
2010-09-08 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201009-06.nasl - Type : ACT_GATHER_INFO |
2010-08-24 | Name : The remote host is missing a Mac OS X update that fixes security issues. File : macosx_SecUpd2010-005.nasl - Type : ACT_GATHER_INFO |
2010-04-28 | Name : The remote SuSE 9 host is missing a security-related patch. File : suse9_12610.nasl - Type : ACT_GATHER_INFO |
2010-04-26 | Name : The remote openSUSE host is missing a security update. File : suse_11_0_clamav-100414.nasl - Type : ACT_GATHER_INFO |
2010-04-26 | Name : The remote openSUSE host is missing a security update. File : suse_11_1_clamav-100414.nasl - Type : ACT_GATHER_INFO |
2010-04-26 | Name : The remote openSUSE host is missing a security update. File : suse_11_2_clamav-100414.nasl - Type : ACT_GATHER_INFO |
2010-04-26 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_clamav-6983.nasl - Type : ACT_GATHER_INFO |
2010-04-19 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2010-082.nasl - Type : ACT_GATHER_INFO |
2010-04-09 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-926-1.nasl - Type : ACT_GATHER_INFO |
2010-04-07 | Name : The remote antivirus service is vulnerable to a file scan evasion attack. File : clamav_0_96.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 12:06:42 |
|