Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:STC:DL:CLAMAV-PE-INT

Severity

Major

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

ClamAV libclamav PE File Handling Integer Overflow

Release Date

2010/09/27

Update Number

1779

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: ClamAV libclamav PE File Handling Integer Overflow


This signature detects attempts to exploit a known vulnerability in ClamAV Antivirus. A successful attack can lead to a integer overflow and arbitrary remote code execution within the context of the process's user.

Extended Description

ClamAV is prone to a heap-corruption vulnerability and an integer-overflow vulnerability. Successfully exploiting these issues allows remote attackers to execute arbitrary machine code in the context of the affected application. This facilitates the remote compromise of affected computers. Failed exploit attempts likely result in application crashes. Versions prior to ClamAV 0.92.1 are affected by these issues.

Affected Products

  • Apple mac_os_x_server 10.5
  • Apple mac_os_x_server 10.5.1
  • Apple mac_os_x_server 10.5.2
  • Clam_anti-virus clamav 0.51.0
  • Clam_anti-virus clamav 0.52.0
  • Clam_anti-virus clamav 0.53.0
  • Clam_anti-virus clamav 0.54.0
  • Clam_anti-virus clamav 0.60.0
  • Clam_anti-virus clamav 0.65.0
  • Clam_anti-virus clamav 0.67.0
  • Clam_anti-virus clamav 0.68.0
  • Clam_anti-virus clamav 0.68.0 -1
  • Clam_anti-virus clamav 0.70.0
  • Clam_anti-virus clamav 0.75.1
  • Clam_anti-virus clamav 0.80.0
  • Clam_anti-virus clamav 0.80.0 Rc1
  • Clam_anti-virus clamav 0.80.0 Rc2
  • Clam_anti-virus clamav 0.80.0 Rc3
  • Clam_anti-virus clamav 0.80.0 Rc4
  • Clam_anti-virus clamav 0.81.0
  • Clam_anti-virus clamav 0.82.0
  • Clam_anti-virus clamav 0.83.0
  • Clam_anti-virus clamav 0.84.0
  • Clam_anti-virus clamav 0.84.0 Rc1
  • Clam_anti-virus clamav 0.84.0 Rc2
  • Clam_anti-virus clamav 0.85.0
  • Clam_anti-virus clamav 0.85.1
  • Clam_anti-virus clamav 0.86.0
  • Clam_anti-virus clamav 0.86.0 .1
  • Clam_anti-virus clamav 0.86.2
  • Clam_anti-virus clamav 0.87.0
  • Clam_anti-virus clamav 0.87.0 -1
  • Clam_anti-virus clamav 0.87.1
  • Clam_anti-virus clamav 0.88.0
  • Clam_anti-virus clamav 0.88.1
  • Clam_anti-virus clamav 0.88.2
  • Clam_anti-virus clamav 0.88.3
  • Clam_anti-virus clamav 0.88.4
  • Clam_anti-virus clamav 0.88.5
  • Clam_anti-virus clamav 0.88.6
  • Clam_anti-virus clamav 0.90.0
  • Clam_anti-virus clamav 0.90.1
  • Clam_anti-virus clamav 0.90.2
  • Clam_anti-virus clamav 0.90.3
  • Clam_anti-virus clamav 0.91
  • Clam_anti-virus clamav 0.91.1
  • Clam_anti-virus clamav 0.91.2
  • Clam_anti-virus clamav 0.92
  • Debian linux 4.0
  • Debian linux 4.0 Alpha
  • Debian linux 4.0 Amd64
  • Debian linux 4.0 Arm
  • Debian linux 4.0 Hppa
  • Debian linux 4.0 Ia-32
  • Debian linux 4.0 Ia-64
  • Debian linux 4.0 M68k
  • Debian linux 4.0 Mips
  • Debian linux 4.0 Mipsel
  • Debian linux 4.0 Powerpc
  • Debian linux 4.0 S/390
  • Debian linux 4.0 Sparc
  • Gentoo linux
  • Kolab kolab_groupware_server 2.0.1
  • Kolab kolab_groupware_server 2.0.2
  • Kolab kolab_groupware_server 2.0.3
  • Kolab kolab_groupware_server 2.0.4
  • Kolab kolab_groupware_server 2.1.0
  • Kolab kolab_groupware_server 2.1Beta2
  • Kolab kolab_groupware_server 2.2 Beta1
  • Kolab kolab_groupware_server 2.2 Beta3
  • Kolab kolab_groupware_server 2.2-Rc1
  • Mandriva corporate_server 3.0.0
  • Mandriva corporate_server 3.0.0 X86 64
  • Mandriva corporate_server 4.0
  • Mandriva corporate_server 4.0.0 X86 64
  • Mandriva linux_mandrake 2007.1
  • Mandriva linux_mandrake 2007.1 X86 64
  • Mandriva linux_mandrake 2008.0
  • Mandriva linux_mandrake 2008.0 X86 64
  • Mandriva linux_mandrake 2008.1
  • Mandriva linux_mandrake 2008.1 X86 64
  • Red_hat fedora 7
  • Red_hat fedora 8
  • Suse core 9
  • Suse linux_openexchange_server
  • Suse linux_personal 10.0.0 OSS
  • Suse linux_personal 10.1
  • Suse linux_professional 10.0.0 OSS
  • Suse linux_professional 10.1
  • Suse novell_linux_desktop 9.0.0
  • Suse novell_linux_pos 9
  • Suse open-enterprise-server
  • Suse opensuse 10.2
  • Suse opensuse 10.3
  • Suse suse_core_9_for_x86
  • Suse suse_linux_enterprise_desktop 10 SP1
  • Suse suse_linux_enterprise_sdk 10.SP1
  • Suse suse_linux_enterprise_server 10 SP1
  • Suse suse_linux_enterprise_server 8
  • Suse suse_linux_enterprise_server 9
  • Suse suse_linux_openexchange_server 4.0.0
  • Suse suse_linux_retail_solution 8.0.0
  • Suse suse_linux_school_server_for_i386
  • Suse suse_linux_standard_server 8.0.0
  • Suse unitedlinux 1.0.0

References

  • BugTraq: 27751
  • CVE: CVE-2008-0318

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out