Submitted by JamesStrandboge on Mon, 2009-04-13 18:59
Description:
===========================================================
Ubuntu Security Notice USN-756-1 April 13, 2009
clamav vulnerability
https://launchpad.net/bugs/360502
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.10:
libclamav5 0.94.dfsg.2-1ubuntu0.3
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that ClamAV did not properly verify buffers when
processing Upack files. A remote attacker could send a crafted file and
cause a denial of service via application crash.


