SuSE has released a security patch to correct two vulnerabilities identified in Clam AntiVirus. The first flaw is caused due to an unspecified error, which causes ClamAV to crash when scanning archives compressed using Quantum compression. The second issue is caused due to a design error in ClamAV's Sendmail milter that requires it to wait for all existing connections to terminate and at the same time reject new connections, which could be exploited to cause a denial of service.
ChangeLog
2005-06-30 : Initial release
Vulnerability Management
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.