星球 - USN-1031-1: ClamAV vulnerabilities
作者:SecurityTeam | 來自:Ubuntu security notices | 2010/12/10 8:13:43
Referenced CVEs:
CVE-2010-4260, CVE-2010-4261, CVE-2010-4479
Description:
===========================================================
Ubuntu Security Notice USN-1031-1 December 10, 2010
clamav vulnerabilities
CVE-2010-4260, CVE-2010-4261, CVE-2010-4479
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 10.04 LTS
Ubuntu 10.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 10.04 LTS:
libclamav6 0.96.3+dfsg-2ubuntu1.0.10.04.2
Ubuntu 10.10:
libclamav6 0.96.3+dfsg-2ubuntu1.2
In general, a standard system update will make all the necessary changes.
Details follow:
Arkadiusz Miskiewicz and others discovered that the PDF processing
code in libclamav improperly validated input. This could allow a
remote attacker to craft a PDF document that could crash clamav or
possibly execute arbitrary code. (CVE-2010-4260, CVE-2010-4479)
It was discovered that an off-by-one error in the icon_cb function
in pe_icons.c in libclamav could allow an attacker to corrupt
memory, causing clamav to crash or possibly execute arbitrary code.
(CVE-2010-4261)
In the default installation, attackers would be isolated by the
clamav AppArmor profile.