Mandriva Linux Security Advisory : clamav (MDVSA-2008:189-1)

This script is Copyright (C) 2009-2016 Tenable Network Security, Inc.

Synopsis :

The remote Mandriva Linux host is missing one or more security

Description :

Multiple vulnerabilities were discovered in ClamAV and corrected with
the 0.94 release, including :

A vulnerability in ClamAV's chm-parser allowed remote attackers to
cause a denial of service (application crash) via a malformed CHM file

A vulnerability in libclamav would allow attackers to cause a denial
of service via vectors related to an out-of-memory condition

Multiple memory leaks were found in ClamAV that could possibly allow
attackers to cause a denial of service via excessive memory
consumption (CVE-2008-3913).

A number of unspecified vulnerabilities in ClamAV were reported that
have an unknown impact and attack vectors related to file descriptor
leaks (CVE-2008-3914).

Other bugs have also been corrected in 0.94 which is being provided
with this update. Because this new version has increased the major of
the libclamav library, updated dependent packages are also being

Update :

The previous update had experimental support enabled, which caused
ClamAV to report the version as 0.94-exp rather than 0.94, causing
ClamAV to produce bogus warnings about the installation being
outdated. This update corrects that problem.

Solution :

Update the affected packages.

Risk factor :

Critical / CVSS Base Score : 10.0
CVSS Temporal Score : 8.7
Public Exploit Available : false

Family: Mandriva Local Security Checks

Nessus Plugin ID: 38032 (mandriva_MDVSA-2008-189.nasl)

Bugtraq ID: 30994

CVE ID: CVE-2008-1389

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now