Release date: 2011-10-08
Updated on: 2011-11-08
Affected Systems:
ClamAV 0.x
Unaffected system:
ClamAV 0.97.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50183
Cve id: CVE-2011-3627
Clam AntiVirus is a Unix GPL AntiVirus tool kit, which is used by many email gateway products.
ClamAV has a denial-of-service vulnerability in recursive processing. Remote attackers can exploit this vulnerability to crash the affected application and cause denial of service to legitimate users.
<* Source: vendor
Link: http://permalink.gmane.org/gmane.comp.security.oss.general/6028
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
ClamAV
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.clamav.net/