From a24567fbc43f221b14e805f9bc0b7c6d16911c46 Mon Sep 17 00:00:00 2001 From: Alex Legler Date: Sun, 8 Mar 2015 22:02:38 +0100 Subject: Import existing advisories --- glsa-200612-18.xml | 61 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 61 insertions(+) create mode 100644 glsa-200612-18.xml (limited to 'glsa-200612-18.xml') diff --git a/glsa-200612-18.xml b/glsa-200612-18.xml new file mode 100644 index 00000000..75500e4d --- /dev/null +++ b/glsa-200612-18.xml @@ -0,0 +1,61 @@ + + + + + + + ClamAV: Denial of Service + + ClamAV is vulnerable to Denial of Service. + + clamav + December 18, 2006 + December 18, 2006: 01 + 157698 + remote + + + 0.88.7 + 0.88.7 + + + +

+ ClamAV is a GPL virus scanner. +

+
+ +

+ Hendrik Weimer discovered that ClamAV fails to properly handle deeply + nested MIME multipart/mixed content. +

+
+ +

+ By sending a specially crafted email with deeply nested MIME + multipart/mixed content an attacker could cause ClamAV to crash. +

+
+ +

+ There is no known workaround at this time. +

+
+ +

+ All ClamAV users should upgrade to the latest version: +

+ + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-antivirus/clamav-0.88.7" +
+ + CVE-2006-6481 + + + jaervosz + + + vorlon + +
-- cgit v1.2.3-65-gdbad