Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:STC:DL:CLAMAV-PE-INT

Severity

High

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

ClamAV libclamav PE File Handling Integer Overflow

Release Date

2010/09/27

Update Number

1779

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: ClamAV libclamav PE File Handling Integer Overflow


This signature detects attempts to exploit a known vulnerability in ClamAV Antivirus. A successful attack can lead to a integer overflow and arbitrary remote code execution within the context of the process's user.

Extended Description

ClamAV is prone to a heap-corruption vulnerability and an integer-overflow vulnerability. Successfully exploiting these issues allows remote attackers to execute arbitrary machine code in the context of the affected application. This facilitates the remote compromise of affected computers. Failed exploit attempts likely result in application crashes. Versions prior to ClamAV 0.92.1 are affected by these issues.

Affected Products

  • Apple Mac OS X Server 10.5
  • Apple Mac OS X Server 10.5.1
  • Apple Mac OS X Server 10.5.2
  • Clam Anti-Virus ClamAV 0.51.0
  • Clam Anti-Virus ClamAV 0.52.0
  • Clam Anti-Virus ClamAV 0.53.0
  • Clam Anti-Virus ClamAV 0.54.0
  • Clam Anti-Virus ClamAV 0.60.0
  • Clam Anti-Virus ClamAV 0.65.0
  • Clam Anti-Virus ClamAV 0.67.0
  • Clam Anti-Virus ClamAV 0.68.0
  • Clam Anti-Virus ClamAV 0.68.0 -1
  • Clam Anti-Virus ClamAV 0.70.0
  • Clam Anti-Virus ClamAV 0.75.1
  • Clam Anti-Virus ClamAV 0.80.0
  • Clam Anti-Virus ClamAV 0.80.0 Rc1
  • Clam Anti-Virus ClamAV 0.80.0 Rc2
  • Clam Anti-Virus ClamAV 0.80.0 Rc3
  • Clam Anti-Virus ClamAV 0.80.0 Rc4
  • Clam Anti-Virus ClamAV 0.81.0
  • Clam Anti-Virus ClamAV 0.82.0
  • Clam Anti-Virus ClamAV 0.83.0
  • Clam Anti-Virus ClamAV 0.84.0
  • Clam Anti-Virus ClamAV 0.84.0 Rc1
  • Clam Anti-Virus ClamAV 0.84.0 Rc2
  • Clam Anti-Virus ClamAV 0.85.0
  • Clam Anti-Virus ClamAV 0.85.1
  • Clam Anti-Virus ClamAV 0.86.0
  • Clam Anti-Virus ClamAV 0.86.0 .1
  • Clam Anti-Virus ClamAV 0.86.2
  • Clam Anti-Virus ClamAV 0.87.0
  • Clam Anti-Virus ClamAV 0.87.0 -1
  • Clam Anti-Virus ClamAV 0.87.1
  • Clam Anti-Virus ClamAV 0.88.0
  • Clam Anti-Virus ClamAV 0.88.1
  • Clam Anti-Virus ClamAV 0.88.2
  • Clam Anti-Virus ClamAV 0.88.3
  • Clam Anti-Virus ClamAV 0.88.4
  • Clam Anti-Virus ClamAV 0.88.5
  • Clam Anti-Virus ClamAV 0.88.6
  • Clam Anti-Virus ClamAV 0.90.0
  • Clam Anti-Virus ClamAV 0.90.1
  • Clam Anti-Virus ClamAV 0.90.2
  • Clam Anti-Virus ClamAV 0.90.3
  • Clam Anti-Virus ClamAV 0.91
  • Clam Anti-Virus ClamAV 0.91.1
  • Clam Anti-Virus ClamAV 0.91.2
  • Clam Anti-Virus ClamAV 0.92
  • Debian Linux 4.0
  • Debian Linux 4.0 Alpha
  • Debian Linux 4.0 Amd64
  • Debian Linux 4.0 Arm
  • Debian Linux 4.0 Hppa
  • Debian Linux 4.0 Ia-32
  • Debian Linux 4.0 Ia-64
  • Debian Linux 4.0 M68k
  • Debian Linux 4.0 Mips
  • Debian Linux 4.0 Mipsel
  • Debian Linux 4.0 Powerpc
  • Debian Linux 4.0 S/390
  • Debian Linux 4.0 Sparc
  • Gentoo Linux
  • Kolab Kolab Groupware Server 2.0.1
  • Kolab Kolab Groupware Server 2.0.2
  • Kolab Kolab Groupware Server 2.0.3
  • Kolab Kolab Groupware Server 2.0.4
  • Kolab Kolab Groupware Server 2.1.0
  • Kolab Kolab Groupware Server 2.1Beta2
  • Kolab Kolab Groupware Server 2.2 Beta1
  • Kolab Kolab Groupware Server 2.2 Beta3
  • Kolab Kolab Groupware Server 2.2-Rc1
  • Mandriva Corporate Server 3.0.0
  • Mandriva Corporate Server 3.0.0 X86 64
  • Mandriva Corporate Server 4.0
  • Mandriva Corporate Server 4.0.0 X86 64
  • Mandriva Linux Mandrake 2007.1
  • Mandriva Linux Mandrake 2007.1 X86 64
  • Mandriva Linux Mandrake 2008.0
  • Mandriva Linux Mandrake 2008.0 X86 64
  • Mandriva Linux Mandrake 2008.1
  • Mandriva Linux Mandrake 2008.1 X86 64
  • Red Hat Fedora 7
  • Red Hat Fedora 8
  • SuSE CORE 9
  • SuSE Linux Openexchange Server
  • SuSE Linux Personal 10.0.0 OSS
  • SuSE Linux Personal 10.1
  • SuSE Linux Professional 10.0.0 OSS
  • SuSE Linux Professional 10.1
  • SuSE Novell Linux Desktop 9.0.0
  • SuSE Novell Linux POS 9
  • SuSE Open-Enterprise-Server
  • SuSE openSUSE 10.2
  • SuSE openSUSE 10.3
  • SuSE SUSE CORE 9 for x86
  • SuSE SUSE Linux Enterprise Desktop 10 SP1
  • SuSE SUSE Linux Enterprise SDK 10.SP1
  • SuSE SUSE Linux Enterprise Server 10 SP1
  • SuSE SUSE Linux Enterprise Server 8
  • SuSE SUSE Linux Enterprise Server 9
  • SuSE SuSE Linux Openexchange Server 4.0.0
  • SuSE SUSE LINUX Retail Solution 8.0.0
  • SuSE SuSE Linux School Server for i386
  • SuSE SuSE Linux Standard Server 8.0.0
  • SuSE UnitedLinux 1.0.0

References

  • BugTraq: 27751
  • CVE: CVE-2008-0318

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out