ClamAV "cli_scanpe ()" Buffer Overflow Vulnerability
Release date:
Updated on:
Affected Systems:
ClamAV <0.98.5
Description:
CVE (CAN) ID: CVE-2014-9050
Clam AntiVirus is a Unix GPL AntiVirus tool kit, which is used by many email gateway products.
ClamAV versions earlier than 0.98.5 encountered an error in implementation of the cli_scanpe () function (libclamav/pe. c). Attackers can exploit this vulnerability to cause heap buffer overflow and arbitrary code execution.
<* Source: Damien Millescamp
Link: http://secunia.com/advisories/62542/
*>
Suggestion:
Vendor patch:
ClamAV
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://blog.clamav.net/2014/11/clamav-0985-has-been-released.html
Completely open-source anti-virus software ClamAV
Install Comodo Antivirus in Linux
Build ClamAV in Linux
This article permanently updates the link address: