FreeBSD : clamav -- Multiple Vulnerabilities (6a5174bd-c580-11da-9110-00123ffe8333)

Critical Nessus Plugin ID 21446

New! Vulnerability Priority Rating (VPR)

Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.

VPR Score: 5.9

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

Secunia reports :

Some vulnerabilities have been reported in ClamAV, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.

An unspecified integer overflow error exists in the PE header parser in 'libclamav/pe.c'. Successful exploitation requires that the ArchiveMaxFileSize option is disabled.

Some format string errors in the logging handling in 'shared/output.c' may be exploited to execute arbitrary code.

An out-of-bounds memory access error in the 'cli_bitset_test()' function in 'ibclamav/others.c' may be exploited to cause a crash.

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?211e856e

Plugin Details

Severity: Critical

ID: 21446

File Name: freebsd_pkg_6a5174bdc58011da911000123ffe8333.nasl

Version: 1.14

Type: local

Published: 2006/05/13

Updated: 2019/08/02

Dependencies: 12634

Risk Information

Risk Factor: Critical

VPR Score: 5.9

CVSS v2.0

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:clamav, p-cpe:/a:freebsd:freebsd:clamav-devel, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2006/04/06

Vulnerability Publication Date: 2006/04/06

Reference Information

CVE: CVE-2006-1614, CVE-2006-1615, CVE-2006-1630

DSA: 1024

Secunia: 19534