漏洞信息详情
ClamAV多个安全漏洞
- CNNVD编号:CNNVD-200604-060
- 危害等级: 中危
- CVE编号:
CVE-2006-1630
- 漏洞类型:
资料不足
- 发布时间:
2005-11-07
- 威胁类型:
远程
- 更新时间:
2006-04-07
- 厂 商:
clam_anti-virus - 漏洞来源:
Damian Put pucik@c… -
漏洞简介
Clam AntiVirus是Unix的GPL杀毒工具包,很多邮件网关产品都在使用。
ClamAV中存在多个安全漏洞,可能允许恶意用户导致拒绝服务并入侵系统。
1) libclamav/pe.c的cli_scanpe()函数的PE首部解析程序存在整数溢出漏洞。攻击者可以通过特制的UPX文件导致堆溢出并执行任意代码。
成功攻击要求禁用了ArchiveMaxFileSize选项。
2) shared/output.c中的日志处理时的一些格式串错误可能允许执行任意代码。
3) ibclamav/others.c的cli_bitset_test()函数中的越界内存访问错误可能导致崩溃。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Clam Anti-Virus ClamAV 0.51
Clam Anti-Virus clamav-0.88.1.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.1.tar.gz
Clam Anti-Virus ClamAV 0.52
Clam Anti-Virus clamav-0.88.1.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.1.tar.gz
Clam Anti-Virus ClamAV 0.53
Clam Anti-Virus clamav-0.88.1.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.1.tar.gz
Clam Anti-Virus ClamAV 0.54
Clam Anti-Virus clamav-0.88.1.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.1.tar.gz
Clam Anti-Virus ClamAV 0.60
Clam Anti-Virus clamav-0.88.1.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.1.tar.gz
Clam Anti-Virus ClamAV 0.65
Clam Anti-Virus clamav-0.88.1.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.1.tar.gz
Clam Anti-Virus ClamAV 0.67
Clam Anti-Virus clamav-0.88.1.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.1.tar.gz
SuSE clamav-0.88.1-0.4.i586.rpm
SUSE LINUX 9.1:
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/clamav-0.88.1-0.4 .i586.rpm
SuSE clamav-0.88.1-0.4.x86_64.rpm
SUSE LINUX 9.1:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/clamav-0.88.1 -0.4.x86_64.rpm
Clam Anti-Virus ClamAV 0.68
Clam Anti-Virus clamav-0.88.1.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.1.tar.gz
Clam Anti-Virus ClamAV 0.68 -1
Clam Anti-Virus clamav-0.88.1.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.1.tar.gz
Clam Anti-Virus ClamAV 0.70
Clam Anti-Virus clamav-0.88.1.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.1.tar.gz
Clam Anti-Virus ClamAV 0.75.1
Clam Anti-Virus clamav-0.88.1.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.1.tar.gz
Clam Anti-Virus ClamAV 0.80 rc4
Clam Anti-Virus clamav-0.88.1.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.1.tar.gz
Clam Anti-Virus ClamAV 0.80
Clam Anti-Virus clamav-0.88.1.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.1.tar.gz
Clam Anti-Virus ClamAV 0.80 rc3
Clam Anti-Virus clamav-0.88.1.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.1.tar.gz
SuSE clamav-0.88.1-0.2.i586.rpm
SUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/clamav-0.88.1-0.2 .i586.rpm
SuSE clamav-0.88.1-0.2.x86_64.rpm
SUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/clamav-0.88.1-0 .2.x86_64.rpm
Clam Anti-Virus ClamAV 0.80 rc1
Clam Anti-Virus clamav-0.88.1.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.1.tar.gz
Clam Anti-Virus ClamAV 0.80 rc2
Clam Anti-Virus clamav-0.88.1.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.1.tar.gz
Clam Anti-Virus ClamAV 0.81
Clam Anti-Virus clamav-0.88.1.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.1.tar.gz
Clam Anti-Virus ClamAV 0.82
Clam Anti-Virus clamav-0.88.1.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.1.tar.gz
Clam Anti-Virus ClamAV 0.83
Clam Anti-Virus clamav-0.88.1.tar.gz
http://prdownloads.sourceforge.net/clamav/clamav-0.88.1.tar.gz
Mandriva clamav-0.88.1-0.1.102mdk.i586.rpm
Mandriva Linux 10.2:
http://www.mandriva.com/en/download
Mandriva clamav-0.88.1-0.1.102mdk.src.rpm
Mandriva Linux 10.2:
http://www.mandriva.com/en/download
Mandriva clamav-0.88.1-0.1.102mdk.x86_64.rpm
Mandriva Linux 10.2:
http://www.mandriva.com/en/download
Mandriva clamav-db-0.88.1-0.1.102mdk.i586.rpm
Mandriva Linux 10.2:
http://www.mandriva.com/en/download
Mandriva clamav-db-0.88.1-0.1.102mdk.x86_64.rpm
Mandriva Linux 10.2:
http://www.mandriva.com/en/download
Mandriva clamav-milter-0.88.1-0.1.102mdk.i586.rpm
Mandriva Linux 10.2:
http://www.mandriva.com/en/download
Mandriva clamav-milter-0.88.1-0.1.102mdk.x86_64.rpm
Mandriva Linux 10.2:
http://www.mandriva.com/en/download
Mandriva clamd-0.88.1-0.1.102mdk.i586.rpm
Mandriva Linux 10.2:
http://www.mandriva.com/en/download
Mandriva clamd-0.88.1-0.1.102mdk.x86_64.rpm
Mandriva Linux 10.2:
http://www.mandriva.com/en/download
Mandriva l
参考网址
来源: US-CERT
名称: TA06-132A
链接:http://www.us-cert.gov/cas/techalerts/TA06-132A.html
来源: VUPEN
名称: ADV-2006-1258
链接:http://www.frsirt.com/english/advisories/2006/1258
来源: DEBIAN
名称: DSA-1024
链接:http://www.debian.org/security/2006/dsa-1024
来源: sourceforge.net
链接:http://sourceforge.net/project/shownotes.php?release_id=407078&group_id=86638
来源: SECUNIA
名称: 19536
链接:http://secunia.com/advisories/19536
来源: SECUNIA
名称: 19534
链接:http://secunia.com/advisories/19534
来源: BID
名称: 17388
链接:http://www.securityfocus.com/bid/17388
来源: XF
名称: clamav-others-dos(25662)
链接:http://xforce.iss.net/xforce/xfdb/25662
来源: TRUSTIX
名称: 2006-0020
链接:http://www.trustix.org/errata/2006/0020
来源: BID
名称: 17951
链接:http://www.securityfocus.com/bid/17951
来源: OSVDB
名称: 24459
来源: MANDRIVA
名称: MDKSA-2006:067
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:067
来源: GENTOO
名称: GLSA-200604-06
链接:http://www.gentoo.org/security/en/glsa/glsa-200604-06.xml
来源: VUPEN
名称: ADV-2006-1779
链接:http://www.frsirt.com/english/advisories/2006/1779
来源: up2date.astaro.com
链接:http://up2date.astaro.com/2006/05/low_up2date_6202.html
来源: SECUNIA
名称: 23719
链接:http://secunia.com/advisories/23719
来源: SECUNIA
名称: 20077
链接:http://secunia.com/advisories/20077
来源: SECUNIA
名称: 19608
链接:http://secunia.com/advisories/19608
来源: SECUNIA
名称: 19570
链接:http://secunia.com/advisories/19570
来源: SECUNIA
名称: 19567
链接:http://secunia.com/advisories/19567
来源: SECUNIA
名称: 19564
链接:http://secunia.com/advisories/19564
来源: SUSE
名称: SUSE-SA:2006:020
链接:http://lists.suse.com/archive/suse-security-announce/2006-Apr/0002.html
来源: APPLE
名称: APPLE-SA-2006-05-11
链接:http://lists.apple.com/archives/security-announce/2006/May/msg00003.html
来源: MANDRIVA
名称: MDKSA-2006:067
链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:067