ClamAV: Denial of Service A vulnerability has been discovered in ClamAV, allowing for a Denial of Service. clamav 2007-08-09 2007-08-09 185013 remote 0.91 0.91

ClamAV is a GPL virus scanner.

Metaeye Security Group reported a NULL pointer dereference in ClamAV when processing RAR archives.

A remote attacker could send a specially crafted RAR archive to the clamd daemon, resulting in a crash and a Denial of Service.

There is no known workaround at this time.

All ClamAV users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=app-antivirus/clamav-0.91"
CVE-2007-3725 falco p-y p-y