[rock-user] [Security Announcement] clamav (RLSA-20060407-01)

"Daniel Jahre" <[email protected]> Fri, 7 Apr 2006 16:55:51 +0200
Newsgroups gmane.linux.distributions.rock.user
Message-ID <[email protected]>
This is a ROCK Linux Security Announcement.

Package: clamav
Announcement ID: RLSA-20060407-01
Date: 2006-04-07
Affected Distributions: none
Affected Releases: none
Cross References:  DSA-1024-1, CVE-2006-1614, CVE-2006-1615, CVE-2006-1630
Fixed at trunk revision: 7479

Content of this advisory:
1) Problem Description
2) Solution or Work-Around
3) Special instructions and notes
4) Updateing your source tree
5) Source package update
6) Binary package update

--------------------------------------------------------------------------------

1) Problem Description
There are multiple issues with clamav versions prior 0.88.1

# CVE-2006-1614
Damian Put discovered an integer overflow in the PE header parser.
This is only exploitable if the ArchiveMaxFileSize option is disabled.

# CVE-2006-1615
Format string vulnerabilities in the logging code have been
discovered, which might lead to the execution of arbitrary code.

# CVE-2006-1630
David Luyer discovered, that ClamAV can be tricked into an invalid
memory access in the cli_bitset_set() function, which may lead to a
denial of service.

2) Solution or Workaround
Please update the package.

3) Special instruction and notes
Restart clamav after update.

4) Updateing your source tree
If you are using a subversion checkout of trunk, run:
 svn up

If you are using submaster run,
 sm sync
to merge the update from trunk into your tree

5) Source package update
As a user of an affected distribution you can update this package by
rebuilding it on your machine
run
 rocket updsrc
to update your local sources and
 rocket emerge clamav
to install the updated package

6) Binary package update
there are no new binary packages available for this package yet.