Mandrake Linux Security Advisory : clamav (MDKSA-2006:138)

High Nessus Plugin ID 23887


The remote Mandrake Linux host is missing one or more security updates.


Damian Put discovered a boundary error in the UPX extraction module in ClamAV which is used to unpack PE Windows executables. This could be abused to cause a Denial of Service issue and potentially allow for the execution of arbitrary code with the permissions of the user running clamscan or clamd.

Updated packages have been patched to correct this issue.


Update the affected packages.

Plugin Details

Severity: High

ID: 23887

File Name: mandrake_MDKSA-2006-138.nasl

Version: $Revision: 1.13 $

Type: local

Published: 2006/12/16

Modified: 2013/05/31

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:clamav, p-cpe:/a:mandriva:linux:clamav-db, p-cpe:/a:mandriva:linux:clamav-milter, p-cpe:/a:mandriva:linux:clamd, p-cpe:/a:mandriva:linux:lib64clamav1, p-cpe:/a:mandriva:linux:lib64clamav1-devel, p-cpe:/a:mandriva:linux:libclamav1, p-cpe:/a:mandriva:linux:libclamav1-devel, cpe:/o:mandriva:linux:2006

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 2006/08/08

Reference Information

CVE: CVE-2006-4018

MDKSA: 2006:138