SUSE-SA:2005:038: clamav

Medium Nessus Plugin ID 19247

Synopsis

The remote host is missing a vendor-supplied security patch

Description

The remote host is missing the patch for the advisory SUSE-SA:2005:038 (clamav).


This security update upgrades the Clamav virus scan engine to the version 0.68.1.

Among other bugfixes and improvements, this update fixes a bug in the Quantum decompressor routines that can be used for a remote denial of service attack against clamd.

This bug is tracked by the Mitre CVE ID CVE-2005-2056.

Also the Clam AV Mail Filter (clamav-milter) Plugin when used in sendmail could be used for a remote denial of service attack.

This bug is tracked by the Mitre CVE ID CVE-2005-2070.

Solution

http://www.suse.de/security/advisories/2005_38_clamav.html

Plugin Details

Severity: Medium

ID: 19247

File Name: suse_SA_2005_038.nasl

Version: 1.6

Agent: unix

Published: 2005/07/20

Dependencies: 12634

Risk Information

Risk Factor: Medium

Vulnerability Information

Required KB Items: Host/SuSE/rpm-list