Short Name |
HTTP:STC:DL:CLAMAV-PE-INT |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
ClamAV libclamav PE File Handling Integer Overflow |
Release Date |
2010/09/27 |
Update Number |
1779 |
Supported Platforms |
idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability in ClamAV Antivirus. A successful attack can lead to a integer overflow and arbitrary remote code execution within the context of the process's user.
ClamAV is prone to a heap-corruption vulnerability and an integer-overflow vulnerability. Successfully exploiting these issues allows remote attackers to execute arbitrary machine code in the context of the affected application. This facilitates the remote compromise of affected computers. Failed exploit attempts likely result in application crashes. Versions prior to ClamAV 0.92.1 are affected by these issues.