Ubuntu 10.04 LTS / 10.10 : clamav vulnerabilities (USN-1031-1)

Ubuntu Security Notice (C) 2010-2013 Canonical, Inc. / NASL script (C) 2010-2013 Tenable Network Security, Inc.

Synopsis :

The remote Ubuntu host is missing one or more security-related patches.

Description :

Arkadiusz Miskiewicz and others discovered that the PDF processing
code in libclamav improperly validated input. This could allow a
remote attacker to craft a PDF document that could crash clamav or
possibly execute arbitrary code. (CVE-2010-4260, CVE-2010-4479)

It was discovered that an off-by-one error in the icon_cb function in
pe_icons.c in libclamav could allow an attacker to corrupt memory,
causing clamav to crash or possibly execute arbitrary code.

In the default installation, attackers would be isolated by the clamav
AppArmor profile.

Solution :

Update the affected packages.

Risk factor :

High / CVSS Base Score : 7.5
CVSS Temporal Score : 5.5
Public Exploit Available : false

Family: Ubuntu Local Security Checks

Nessus Plugin ID: 51117 ()

Bugtraq ID: 45152

CVE ID: CVE-2010-4260