Bug 132305 (CVE-2005-3501) - VUL-0: CVE-2005-3501: clamav: endless loop and buffer overflow
Summary: VUL-0: CVE-2005-3501: clamav: endless loop and buffer overflow
Status: RESOLVED FIXED
Alias: CVE-2005-3501
Product: SUSE Linux 10.1
Classification: openSUSE
Component: Security (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Normal (vote)
Target Milestone: ---
Assignee: Ludwig Nussel
QA Contact: E-mail List
URL:
Whiteboard: CVE-2005-3501: CVSS v2 Base Score: 4....
Keywords:
Depends on:
Blocks:
 
Reported: 2005-11-04 12:44 UTC by Thomas Biege
Modified: 2019-05-01 14:42 UTC (History)
3 users (show)

See Also:
Found By: Other
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Biege 2005-11-04 12:44:47 UTC
Hi,
a new release from upstream closes some security bugs.

http://sourceforge.net/project/shownotes.php?release_id=368319
Comment 1 Ludwig Nussel 2005-11-07 09:28:38 UTC
CVE-2005-3239 - The OLE2 unpacker in clamd in ClamAV 0.87-1 allows remote attackers to cause a denial of service (segmentation fault) via a DOC file with an invalid property tree, which triggers an infinite recursion in the ole2_walk_property_tree function.

CVE-2005-3303 refers to the fsg.c overflow
Comment 2 Ludwig Nussel 2005-11-07 12:25:48 UTC
Reinhard only works part time only. We need someone to fix this issue quickly. Customers are also already asking for updates.
Comment 3 Ludwig Nussel 2005-11-07 17:04:13 UTC
mmj asked me to do the update this time as there is no backup maintainer. 0.87.1 contains the bugfixes described in the changelog. Only the generated docu makes the diff so huge. Since clamav usually complain at customers about an outdated version I upgrade to 0.87.1.

Maintenance-Tracker-2759
Comment 4 Ludwig Nussel 2005-11-08 08:51:01 UTC
According to Mandriva:

 The tnef_attachment() function allows remote attackers to cause a DoS
 (infinite loop and memory exhaustion) via a crafted value in a CAB file
 that causes ClamAV to repeatedly scan the same block (CVE-2005-3500)

 Remote attackers could cause a DoS (infinite loop) via a crafted CAB
 file (CVE-2005-3501)
Comment 5 Ludwig Nussel 2005-11-09 08:33:17 UTC
updates released
Comment 6 Reinhard Max 2005-11-09 09:41:19 UTC
Thanks, Ludwig for jumping in.
Comment 7 Thomas Biege 2009-10-13 21:46:27 UTC
CVE-2005-3501: CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)