FreeBSD : clamav -- multiple vulnerabilities (903654bd-1927-11dc-b8a0-02e0185f8d72)

critical Nessus Plugin ID 25560

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

Clamav had been found vulnerable to multiple vulnerabilities :

- Improper checking for the end of an buffer causing an unspecified attack vector.

- Insecure temporary file handling, which could be exploited to read sensitive information.

- A flaw in the parser engine which could allow a remote attacker to bypass the scanning of RAR files.

- A flaw in libclamav/unrar.c which could cause a remote Denial of Service (DoS) by sending a specially crafted RAR file with a modified vm_codesize.

- A flaw in the OLE2 parser which could cause a remote Denial of Service (DoS).

Solution

Update the affected package.

See Also

http://www.nessus.org/u?7a42b721

http://www.nessus.org/u?4afca940

Plugin Details

Severity: Critical

ID: 25560

File Name: freebsd_pkg_903654bd192711dcb8a002e0185f8d72.nasl

Version: 1.13

Type: local

Published: 6/21/2007

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:clamav, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 6/19/2007

Vulnerability Publication Date: 4/18/2007

Reference Information

CVE: CVE-2007-2650, CVE-2007-3023, CVE-2007-3024, CVE-2007-3122, CVE-2007-3123