MIME bypass
Bug #76374 reported by
Kees Cook
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
clamav (Ubuntu) |
Fix Released
|
High
|
Unassigned | ||
Dapper |
Fix Released
|
Undecided
|
Unassigned | ||
Edgy |
Fix Released
|
Undecided
|
Unassigned | ||
Feisty |
Fix Released
|
High
|
Unassigned |
Bug Description
Binary package hint: clamav
clamav prior to feisty is vulnerable to MIME decode bypass.
CVE References
Changed in clamav: | |
status: | Confirmed → In Progress |
Changed in clamav: | |
status: | In Progress → Fix Committed |
status: | In Progress → Fix Committed |
Changed in clamav: | |
status: | Fix Committed → Fix Released |
status: | Fix Committed → Fix Released |
To post a comment you must log in.
This is an example mbox file that has whitespace characters in it. On breezy, dapper, edgy, clamscan will scan this file as "OK". However, if you unpack it ("munpack eicar.mbox") and scan eicar.txt, the test signature is found.