Mandriva Linux Security Advisory : clamav (MDVSA-2008:229)

high Nessus Plugin ID 36640

Synopsis

The remote Mandriva Linux host is missing one or more security updates.

Description

An off-by-one error was found in ClamAV versions prior to 0.94.1 that could allow remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted VBA project file (CVE-2008-5050).

Other bugs have also been corrected in 0.94.1 which is being provided with this update.

Solution

Update the affected packages.

Plugin Details

Severity: High

ID: 36640

File Name: mandriva_MDVSA-2008-229.nasl

Version: 1.13

Type: local

Published: 4/23/2009

Updated: 1/6/2021

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:clamav, p-cpe:/a:mandriva:linux:clamav-db, p-cpe:/a:mandriva:linux:clamd, p-cpe:/a:mandriva:linux:lib64clamav-devel, p-cpe:/a:mandriva:linux:lib64clamav5, p-cpe:/a:mandriva:linux:libclamav-devel, p-cpe:/a:mandriva:linux:libclamav5, cpe:/o:mandriva:linux:2008.0, cpe:/o:mandriva:linux:2008.1, cpe:/o:mandriva:linux:2009.0

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 11/14/2008

Reference Information

CVE: CVE-2008-5050

MDVSA: 2008:229

CWE: 119