icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons_061

ClamAV < 0.86.2 Content-parsing Multiple Overflows

High

Synopsis

The remote host is vulnerable to a buffer overflow.

Description

The remote host is running ClamAV, an open-source antivirus solution for Unix-like systems. This version of ClamAV is reported to be vulnerable to a flaw where the parsing of a malicious file will cause the clamav process to overflow system memory, possibly resulting in an attacker executing code. An attacker exploiting this flaw would need to be able to send a specially formed email to the system running ClamAV.

Solution

Upgrade to version 0.86.2 or higher.