
Vulnerability Solutions |
||
| The WatchMouse Periodic Vulnerability Scan checks for the vulnerability below. To see the most recently added vulnerability solutions that are scanned by WatchMouse, go to the Vulnerability Solutions overview | ||
| Category: Gain a shell remotely | Risk factor: Medium | Added: 3 Dec 2008 |
| Synopsis: The remote anti-virus service is vulnerable to a denial of service attack. Description: According to its version, the clamd anti-virus daemon on the remote host is earlier than 0.94.2. There is a recursive stack overflow involving the JPEG parsing code in such versions. A remote attacker may be able to leverage this issue to cause the application to recursively scan a specially crafted JPEG, which will eventually cause it to crash. See also: https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1266 http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLog (look for bb#1266) Solution: Upgrade to ClamAV 0.94.2 or later. Risk factor: Medium / CVSS Base Score : 5.0 (CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:P) |
||
