Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-1100

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2008-1100
Last Modified 07 Mar 2011 10:05:57
Published 14 Apr 2008 12:05:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2008-1100

Summary

Buffer overflow in the cli_scanpe function in libclamav (libclamav/pe.c) for ClamAV 0.92 and 0.92.1 allows remote attackers to execute arbitrary code via a crafted Upack PE file.

Vulnerable Systems

Application

  • Clam Anti-virus Clamav 0.92

  • Clam Anti-virus Clamav 0.92.1


References

CERT - TA08-260A

CERT-VN - VU#858595

VUPEN - ADV-2008-2584

VUPEN - ADV-2008-1218

BID - 28756

GENTOO - GLSA-200805-19

MISC - http://secunia.com/secunia_research/2008-11/advisory/

SECUNIA - 31882

SECUNIA - 29000

APPLE - APPLE-SA-2008-09-15

CONFIRM - https://wwws.clamav.net/bugzilla/show_bug.cgi?id=878

FEDORA - FEDORA-2008-3900

FEDORA - FEDORA-2008-3420

FEDORA - FEDORA-2008-3358

XF - clamav-cliscanpe-bo(41789)

SECTRACK - 1019837

BID - 28784

MANDRIVA - MDVSA-2008:088

DEBIAN - DSA-1549

SECUNIA - 30328

SECUNIA - 30253

SECUNIA - 29975

SECUNIA - 29891

SECUNIA - 29886

SECUNIA - 29863

SUSE - SUSE-SA:2008:024

CONFIRM - http://kolab.org/security/kolab-vendor-notice-20.txt

Related Patches

Apple 2008-09-15 Security Update 2008-006 (PPC)

Apple 2008-09-15 Security Update 2008-006 Server (PPC)

Apple 2008-09-15 Mac OS X 10.5.5 Update

Apple 2008-09-15 Mac OS X Server 10.5.5 Combo Update

Apple 2008-09-15 Mac OS X Server 10.5.5 Update

Apple 2008-09-15 Security Update 2008-006 (Intel)

Apple 2008-09-15 Mac OS X 10.5.5 Combo Update

Apple 2008-09-15 Security Update 2008-006 Server (Intel)


Last Updated: 27 May 2016 10:47:01