clamav in dapper vulnerable to critical heap overflow

Bug #59915 reported by Christiane
256
Affects Status Importance Assigned to Milestone
clamav (Ubuntu)
Fix Released
Undecided
Martin Pitt

Bug Description

clamav_0.88.2-1ubuntu1, which is the most recent package available in dapper as of today, contains the critical heap overflow vunerability as described in:

http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4018

The edgy release already contains the fix.

CVE References

Revision history for this message
Kees Cook (kees) wrote :

Attached is a debdiff for the UPX unpacker fix for dapper's clamav.

Revision history for this message
Kees Cook (kees) wrote :

This is a corrected patch that has a good changelog version and adds a note about the origin of patch.

Revision history for this message
Martin Pitt (pitti) wrote :

Looks good now, will upload.

Changed in clamav:
assignee: nobody → pitti
status: Unconfirmed → Fix Committed
Revision history for this message
Martin Pitt (pitti) wrote :

Released, should be on security.u.c. in about 80 minutes.

Changed in clamav:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.