Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Mageia 3 released
· Understanding Email Bounce Messages and more
· How to Prepare for Windows 8 Even Though Its Not Coming to Enterprises
· Microsoft Office Clone Updates Interface, Improves File Support
· Windows Firewall Control 4.0.0.0 released
· 10 amazing Linux desktop environments you've probably never seen
· Microsoft Office security flaw hits thousands in latest hacker attack
· Kubuntu 13.04 Raring Ringtail Review
· Windows Mobile 7 concept video shows why Microsoft dumped the platform
· Building a Thin Mini-ITX PC and more

Upcoming News
· PowerColor PCS+ HD7870 Gaming Video Card @ TechwareLabs
· Rosewill T600N Wireless Router Review @ ThinkComputers.org
· Google Play Music Review @ TechReviewSource.com
· Adata DashDrive Elite UE700 32GB Flash Drive Review @ Ninjalane
· News: HGST packs 1.5TB into 9.5-mm, three-platter Travelstar 5K1500 notebook drive
· Gigabyte GeForce GTX 650 Ti Boost OC WindForce 2X review
· Metro: Last Light Performance, Benchmarked
· Seidio Active Case Combo for HTC One Review @ TestFreaks
· Jawbone UP Wristband
· Seagate Desktop HDD.15 4TB Hard Drive Review @ Hardware Canucks

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6394 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 662 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4523 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 724 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1120 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » December 2008 » DSA 1680-1: New clamav packages fix potential code execution

DSA 1680-1: New clamav packages fix potential code execution

Posted by Bob on: 12/04/2008 09:30 AM [ Print | 0 comment(s) ]

The Debian Security Team published a new security update for Debian GNU/Linux. Here the announcement:




-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
Debian Security Advisory DSA-1680-1 security@debian.org
http://www.debian.org/security/ Florian Weimer
December 04, 2008 http://www.debian.org/security/faq
- ------------------------------------------------------------------------

Package : clamav
Vulnerability : buffer overflow, stack consumption
Problem type : local (remote)
Debian-specific: no
CVE Id(s) : CVE-2008-5050 CVE-2008-5314
Debian Bug : 505134 507624

Moritz Jodeit discovered that ClamAV, an anti-virus solution, suffers
from an off-by-one-error in its VBA project file processing, leading to
a heap-based buffer overflow and potentially arbitrary code execution
(CVE-2008-5050).

Ilja van Sprundel discovered that ClamAV contains a denial of service
condition in its JPEG file processing because it does not limit the
recursion depth when processing JPEG thumbnails (CVE-2008-5314).

For the stable distribution (etch), these problems have been fixed in
version 0.90.1dfsg-4etch16.

For the unstable distribution (sid), these problems have been fixed in
version 0.94.dfsg.2-1.

The testing distribution (lenny) will be fixed soon.

We recommend that you upgrade your clamav packages.

Upgrade instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 4.0 alias etch
- -------------------------------

Source archives:

http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1dfsg.orig.tar.gz
Size/MD5 checksum: 11610428 6dc18602b0aa653924d47316f9411e49
http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1dfsg-4etch16.dsc
Size/MD5 checksum: 908 ebc60299a69aab41dfdb77e667e2857c
http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1dfsg-4etch16.diff.gz
Size/MD5 checksum: 216130 5ae1da1b6351a13b5c385919960ca9b7

Architecture independent packages:

http://security.debian.org/pool/updates/main/c/clamav/clamav-base_0.90.1dfsg-4etch16_all.deb
Size/MD5 checksum: 201408 63e3898029276baf914fafa347747996
http://security.debian.org/pool/updates/main/c/clamav/clamav-docs_0.90.1dfsg-4etch16_all.deb
Size/MD5 checksum: 1003722 5d316f2ea821b441971b0e05e58e481d
http://security.debian.org/pool/updates/main/c/clamav/clamav-testfiles_0.90.1dfsg-4etch16_all.deb
Size/MD5 checksum: 158564 189a55ca25bdf9e03a0ae3b9f4a565e9

alpha architecture (DEC Alpha)

http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1dfsg-4etch16_alpha.deb
Size/MD5 checksum: 373052 b59a6787be52e776d3b6238bac4e7fff
http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1dfsg-4etch16_alpha.deb
Size/MD5 checksum: 182812 289769066d1883af6c455255725c1c81
http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1dfsg-4etch16_alpha.deb
Size/MD5 checksum: 9305338 e2d5290afa1484ffc3ee6abfc99a7e5f
http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1dfsg-4etch16_alpha.deb
Size/MD5 checksum: 465410 ad42ee7f6355353575f05de54d67fa2b
http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1dfsg-4etch16_alpha.deb
Size/MD5 checksum: 598714 6f862583fe87d09e3c3a3c288c75a787
http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1dfsg-4etch16_alpha.deb
Size/MD5 checksum: 180954 7122cfc98ec69b5b012d9794dc3f44cd
http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1dfsg-4etch16_alpha.deb
Size/MD5 checksum: 862390 df3cb4e88d62cbc641d1c48c14d5c551

amd64 architecture (AMD x86_64 (AMD64))

http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1dfsg-4etch16_amd64.deb
Size/MD5 checksum: 856672 bc8b467814eb5b76b6a165ee7abbbb7d
http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1dfsg-4etch16_amd64.deb
Size/MD5 checksum: 177968 c2aa51b550584931f3f1b7b1f6df6508
http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1dfsg-4etch16_amd64.deb
Size/MD5 checksum: 9302094 cd9f623cfb4f23d1777cf21e830d74b2
http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1dfsg-4etch16_amd64.deb
Size/MD5 checksum: 355706 e0db968192096ac9215ab676b5750c7d
http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1dfsg-4etch16_amd64.deb
Size/MD5 checksum: 179200 99ba1e041488e76a7d6e457ed51536f0
http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1dfsg-4etch16_amd64.deb
Size/MD5 checksum: 341684 6207bf783731c636eaa192d696466a88
http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1dfsg-4etch16_amd64.deb
Size/MD5 checksum: 594608 5e87c000b193a1d25e03580496b91fc2

hppa architecture (HP PA RISC)

http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1dfsg-4etch16_hppa.deb
Size/MD5 checksum: 178252 a2dadc8689fd265609265d65f9ba5cf7
http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1dfsg-4etch16_hppa.deb
Size/MD5 checksum: 178500 e26b37f74b35c6128654305c2d8f68eb
http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1dfsg-4etch16_hppa.deb
Size/MD5 checksum: 373174 c8815805d7a9cf555a1611b7314cbe93
http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1dfsg-4etch16_hppa.deb
Size/MD5 checksum: 573090 724ad2d96fcd7b80e7a1c8c090fb9b04
http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1dfsg-4etch16_hppa.deb
Size/MD5 checksum: 9303992 c463499f12992880b420a015b1bd5d9a
http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1dfsg-4etch16_hppa.deb
Size/MD5 checksum: 857738 1ebd69a77c29a7fc69f02b27b2dad3e6
http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1dfsg-4etch16_hppa.deb
Size/MD5 checksum: 396534 d889914674f27507e6ca759d78d22995

i386 architecture (Intel ia32)

http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1dfsg-4etch16_i386.deb
Size/MD5 checksum: 338494 19d7a1f5ba21bb2ea6ef65477559f94e
http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1dfsg-4etch16_i386.deb
Size/MD5 checksum: 9299810 7128061759b66acac727697fe89b64f1
http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1dfsg-4etch16_i386.deb
Size/MD5 checksum: 176040 be3736249dbc666ba1319b1c90846f6c
http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1dfsg-4etch16_i386.deb
Size/MD5 checksum: 561386 c9d821e32d55ef4a6a2ff6c53dfe5144
http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1dfsg-4etch16_i386.deb
Size/MD5 checksum: 855774 4d455d6519fb958ca80ccd64cf002733
http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1dfsg-4etch16_i386.deb
Size/MD5 checksum: 173110 19bb9a435ec67992ec1f64117bbe4ad5
http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1dfsg-4etch16_i386.deb
Size/MD5 checksum: 340104 febee614772fbd5bf27f05f121651a20

ia64 architecture (Intel ia64)

http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1dfsg-4etch16_ia64.deb
Size/MD5 checksum: 879178 e54e7a00d6997145abf9d0fd29125122
http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1dfsg-4etch16_ia64.deb
Size/MD5 checksum: 611950 4688c0588b2c0289f7d1d1661afab75f
http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1dfsg-4etch16_ia64.deb
Size/MD5 checksum: 9316052 a7621f1da45dc360701bb220375f75fa
http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1dfsg-4etch16_ia64.deb
Size/MD5 checksum: 202432 97d25289436bab9657006c5a3111a46b
http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1dfsg-4etch16_ia64.deb
Size/MD5 checksum: 192686 f749efd1adaa69f02cf333b59c1f8fe0
http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1dfsg-4etch16_ia64.deb
Size/MD5 checksum: 466144 808f94a059ba40b6fb07d9455d09f6aa
http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1dfsg-4etch16_ia64.deb
Size/MD5 checksum: 428106 1be6f7d9cdc26e37f306cf1b17d465ac

mips architecture (MIPS (Big Endian))

http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1dfsg-4etch16_mips.deb
Size/MD5 checksum: 179864 87927a28c832d9591e72b57949c1dc6e
http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1dfsg-4etch16_mips.deb
Size/MD5 checksum: 600956 8e9a4325b6fca6a1233fa9fd0ca0555c
http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1dfsg-4etch16_mips.deb
Size/MD5 checksum: 855252 f6e1334c499c80f63aed3d29e44ae1bf
http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1dfsg-4etch16_mips.deb
Size/MD5 checksum: 398728 e6cd9d013cc52be551eba54b2720b983
http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1dfsg-4etch16_mips.deb
Size/MD5 checksum: 175734 a9282395129b667acb155dbcc2a0b93c
http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1dfsg-4etch16_mips.deb
Size/MD5 checksum: 343690 1c91c1d31700a461afc165781ae2f090
http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1dfsg-4etch16_mips.deb
Size/MD5 checksum: 9301736 4bc34b6d01389eb060b31952c2b1b27b

powerpc architecture (PowerPC)

http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1dfsg-4etch16_powerpc.deb
Size/MD5 checksum: 9303100 e98394d3111c5ff1c612fb3e92a0f8b9
http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1dfsg-4etch16_powerpc.deb
Size/MD5 checksum: 857964 eda098ba91e370a95e9259b651fb684b
http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1dfsg-4etch16_powerpc.deb
Size/MD5 checksum: 177148 8b6840ca3ddf149b2dfa0c20112b63fd
http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1dfsg-4etch16_powerpc.deb
Size/MD5 checksum: 182514 e26515d0a92e205bca5d7e4438c51589
http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1dfsg-4etch16_powerpc.deb
Size/MD5 checksum: 350804 ab54eeb5d022ae08535dd90c9b5df157
http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1dfsg-4etch16_powerpc.deb
Size/MD5 checksum: 372856 999347aba8ba2a6481c33d0656aeaad3
http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1dfsg-4etch16_powerpc.deb
Size/MD5 checksum: 592144 305ef279c3840eb9fb3df233ed258333

s390 architecture (IBM S/390)

http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1dfsg-4etch16_s390.deb
Size/MD5 checksum: 177908 d4a05f341abba5d5de91e328d841518d
http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1dfsg-4etch16_s390.deb
Size/MD5 checksum: 177060 4762fb05719e9ce0cb1ed3cad9c57960
http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1dfsg-4etch16_s390.deb
Size/MD5 checksum: 9301758 1bd5836e2d661378dfa9f4cf9f41091a
http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1dfsg-4etch16_s390.deb
Size/MD5 checksum: 370338 fa23bc8ee8d3f0d85b8b03d933398edb
http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1dfsg-4etch16_s390.deb
Size/MD5 checksum: 582564 a6ee552708c64b6d9dd0b891cc5fb797
http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1dfsg-4etch16_s390.deb
Size/MD5 checksum: 361764 06046ba7e4a989592a2ccca18a6f04a1
http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1dfsg-4etch16_s390.deb
Size/MD5 checksum: 855966 fab4913131e36fb3ee0619e516d60a41

sparc architecture (Sun SPARC/UltraSPARC)

http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1dfsg-4etch16_sparc.deb
Size/MD5 checksum: 349588 6dfb12eb76d35c2d91ae4e6ff1d516e1
http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1dfsg-4etch16_sparc.deb
Size/MD5 checksum: 9298888 ec04c3d9ce44da80eeca6795d695d061
http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1dfsg-4etch16_sparc.deb
Size/MD5 checksum: 357982 cfade6599939f4f83038e5334eaa3a2d
http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1dfsg-4etch16_sparc.deb
Size/MD5 checksum: 542512 ffedc011073a2e0b2028bc700361e949
http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1dfsg-4etch16_sparc.deb
Size/MD5 checksum: 852672 197bb1d08bea1ed5826bba231c54e99f
http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1dfsg-4etch16_sparc.deb
Size/MD5 checksum: 174792 c7136015088cbdc0f3d74769b4c46efb
http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1dfsg-4etch16_sparc.deb
Size/MD5 checksum: 172304 fc4153b27a708f0906ee7c041b67f81b


These files will probably be moved into the stable distribution on
its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show lt;pkggt;' and http://packages.debian.org/lt;pkggt;
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iQEcBAEBAgAGBQJJN5PaAAoJEL97/wQC1SS+UDIH/1Afas/ow3ybjzlwatl2Jx2P
p5yeVwblQCcIDjSj05m9pbPi2KTFpz+ng+/jVRVE1TEcUZngC7aKh4pzV5WJMdSp
gonrUF5APIMJpojRDTY07WNV41dxdCRlhpgNRaM62moHWpP8BtbQf9Wodl4vafZp
S3OoToXaXs2VBGR6V0aJPvRU8StJI0FyUiboHYb9TLKP2k94RufydmZ3NaZaPluC
sDkQ3gfbFDWiRqvcBBqWVBfvbkYHMy5U5/rpWd8uWHfiP9VlXJXd7Wk3cXkgOTgX
aPPb/3qnb96GIN26ZQI+Y1seFfmaHk3roTcSPDk6Mb5bZjEtF7/4TXsBumWv2RQ=
=3Dhc
-----END PGP SIGNATURE-----


Bookmark and Share

« Expanded Apple lawsuit claims Psystar part of a larger plot · Futurelooks Holiday 2008 Guide for Travelling Techie »

Linux Compatible » News » December 2008 » DSA 1680-1: New clamav packages fix potential code execution
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition