This script is Copyright (C) 2010-2014 Tenable Network Security, Inc.
The remote antivirus service is affected by multiple vulnerabilities.
According to its version, the clamd antivirus daemon on the remote
host is earlier than 0.96.3. Such versions are reportedly affected by
multiple vulnerabilities :
- There is a failure to properly parse a specially crafted
PDF file because of insufficient bounds-checks on PDF
files in the 'find_stream_bounds()' function of the
libclamav 'pdf.c' source file. (Bug 2226)
- An integer overflow can be triggered in the
'BZ2_decompress' function when parsing specially crafted
BZ2 files, which could cause the server to crash or
potentially allow execution of arbitrary code. (Bugs
See also :
Upgrade to ClamAV 0.96.3 or later.
Risk factor :
Medium / CVSS Base Score : 5.1
CVSS Temporal Score : 3.8
Public Exploit Available : false