Clam AntiVirus Multiple Denial of Service And Code Execution Vulnerabilities
Title : Clam AntiVirus Multiple Denial of Service And Code Execution Vulnerabilities Advisory ID : FrSIRT/ADV-2007-2952 CVE ID : CVE-2007-4510 - CVE-2007-4560
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-08-23
Multiple vulnerabilities have been identified in Clam AntiVirus (ClamAV), which could be exploited by attackers or malware to cause a denial of service or execute arbitrary code.
The first issue is caused by NULL-pointer dereference errors in the "cli_scanrtf()" [libclamav/rtf.c] and "cli_html_normalise()" [libclamav/htmlnorm.c] when processing malformed RTF or HTML files, which could be exploited by attackers to crash an affected application, creating a denial of service condition [...] References
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.