Australia's Leading Computer Emergency Response Team

AA-2008.0245 -- [Win][UNIX/Linux] -- A denial of service vulnerability has been found in ClamAV
Date: 05 December 2008
Original URL: http://www.auscert.org.au/render.html?cid=37&it=10136
References: ESB-2008.1094  

Click here for PGP verifiable version
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
AA-2008.0245                  AUSCERT Advisory

                             [Win][UNIX/Linux]
        A denial of service vulnerability has been found in ClamAV
                              5 December 2008
- ---------------------------------------------------------------------------

        AusCERT Advisory Summary
        ------------------------

Product:              ClamAV 0.94.1 and prior
Operating System:     UNIX variants (UNIX, Linux, OSX)
                      Windows
Impact:               Denial of Service
Access:               Remote/Unauthenticated
CVE Names:            CVE-2008-5314
Member content until: Thursday, January 01 2009

Revision History:     December  5 2008: Added CVE
                      December  4 2008: Initial Release

OVERVIEW:

        A denial of service vulnerability in ClamAV has been patched in
        version 0.94.2. [1]


DETAILS:

        Lack of recursion checking in version 0.94.1 and prior mean that
        calls to the "cli_check_jpeg_exploit" function could result in a
        recursive stack overflow. This stack overflow has no potential
        to allow execution of code, as it is just stack exhaustion. [1]


MITIGATION:

        The vulnerabilities are corrected in version 0.94.2 of ClamAV. [2]


REFERENCES:

        [1] Bug 1266 - recursive stack overflow in jpeg parsing code
            https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1266

        [2] Clam AntiVirus
            http://www.clamav.net/download/

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

If you believe that your computer system has been compromised or attacked in 
any way, we encourage you to let us know by completing the secure National IT 
Incident Reporting Form at:

        http://www.auscert.org.au/render.html?it=3192

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================

-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQCVAwUBSTiQASh9+71yA2DNAQKvfwP/X3JbfQF6nda9RIAL9zNTV30ONFJEoFgp
kHdY3Qu5IWlK4WCMlgIJn6fv9vWk0eRpQkbUg5fox/2dN42eldA0g1e+4s4CIdHk
itHGSqctGmzAY0pW8/zgTxJtyNJlvqlYHD0IngvEFOKlAqXnsy6CbiEiMVmh0bXh
CJOhiVz8rSE=
=ZfQA
-----END PGP SIGNATURE-----