This script is Copyright (C) 2007-2014 Tenable Network Security, Inc.
The remote host is missing a vendor-supplied security patch
The remote host is missing the patch for the advisory SUSE-SA:2006:078 (clamav).
The anti virus scan engine ClamAV has been updated to version 0.88.7
to fix various security problems:
CVE-2006-5874: Clam AntiVirus (ClamAV) allows remote attackers to
cause a denial of service (crash) via a malformed base64-encoded MIME
attachment that triggers a NULL pointer dereference.
CVE-2006-6481: Clam AntiVirus (ClamAV) 0.88.6 allowed remote attackers
to cause a denial of service (stack overflow and application crash)
by wrapping many layers of multipart/mixed content around a document,
a different vulnerability than CVE-2006-5874 and CVE-2006-6406.
CVE-2006-6406: Clam AntiVirus (ClamAV) 0.88.6 allowed remote attackers
to bypass virus detection by inserting invalid characters into base64
encoded content in a multipart/mixed MIME file, as demonstrated with
the EICAR test file.
Risk factor :
Get Nessus Professional to scan unlimited IPs, run compliance checks & moreBuy Nessus Professional Now