FreeBSD : clamav -- multiple vulnerabilities (903654bd-1927-11dc-b8a0-02e0185f8d72)

Critical Nessus Plugin ID 25560


The remote FreeBSD host is missing a security-related update.


Clamav had been found vulnerable to multiple vulnerabilities :

- Improper checking for the end of an buffer causing an unspecified attack vector.

- Insecure temporary file handling, which could be exploited to read sensitive information.

- A flaw in the parser engine which could allow a remote attacker to bypass the scanning of RAR files.

- A flaw in libclamav/unrar.c which could cause a remote Denial of Service (DoS) by sending a specially crafted RAR file with a modified vm_codesize.

- A flaw in the OLE2 parser which could cause a remote Denial of Service (DoS).


Update the affected package.

See Also

Plugin Details

Severity: Critical

ID: 25560

File Name: freebsd_pkg_903654bd192711dcb8a002e0185f8d72.nasl

Version: $Revision: 1.10 $

Type: local

Published: 2007/06/21

Modified: 2013/06/22

Dependencies: 12634

Risk Information

Risk Factor: Critical


Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:clamav, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2007/06/19

Vulnerability Publication Date: 2007/04/18

Reference Information

CVE: CVE-2007-2650, CVE-2007-3023, CVE-2007-3024, CVE-2007-3122, CVE-2007-3123