Clam AntiVirus: Denial of service A vulnerability in Clam AntiVirus can lead to a Denial of Service condition. clamav 2014-12-09 2014-12-09 529728 remote 0.98.5 0.98.5

Clam AntiVirus is an open source (GPL) anti-virus toolkit for UNIX, designed especially for e-mail scanning on mail gateways.

A heap-based buffer overflow exists in the cli_scanpe function in libclamav/pe.c in ClamAV.

A remote attacker could possibly cause a Denial of Service condition via a specially crafted file.

There is no known workaround at this time.

All Clam AntiVirus users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=app-antivirus/clamav-0.98.5"
CVE-2014-9050 BlueKnight Zlogene