Articles / Ubuntu: New ClamAV packages…

Ubuntu: New ClamAV packages fix security vulnerabilities

It was discovered that the hash processing code in libclamav improperly handled messages with certain hashes. This could allow a remote attacker to craft a document that could cause clamav to crash, resulting in a denial of service. Updated packages are available from security.ubuntu.com.

==========================================================================
Ubuntu Security Notice USN-1179-1
July 28, 2011

clamav vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.04

Summary:

An attacker could send crafted input to ClamAV and cause it to
crash.

Software Description:
- clamav: anti-virus utility for Unix - command-line interface

Details:

It was discovered that the hash processing code in libclamav improperly
handled messages with certain hashes. This could allow a remote attacker to
craft a document that could cause clamav to crash, resulting in a denial of
service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
 libclamav6                      0.97+dfsg-2ubuntu1.1

In general, a standard system update will make all the necessary changes.

References:
 http://www.ubuntu.com/usn/usn-1179-1
 CVE-2011-2721

Package Information:
 https://launchpad.net/ubuntu/+source/clamav/0.97+dfsg-2ubuntu1.1
Screenshot

Project Spotlight

Kigo Video Converter Ultimate for Mac

A tool for converting and editing videos.

Screenshot

Project Spotlight

Kid3

An efficient tagger for MP3, Ogg/Vorbis, and FLAC files.