Home arrow US-CERT Computer Emergency Readiness Team arrow Multiple ClamAV Vulnerabilities

Multiple ClamAV Vulnerabilities

Clam AntiVirus has released ClamAV 0.93 to address multiple vulnerabilities. Two of these vulnerabilities are due to buffer overflow conditions in the handling of Upack executables in libclamav/pe.c and PeSpin packed executables in libclamav/spin.c. There are two additional vulnerabilities due to improper handling of ARJ and RAR archives. Exploitation of these vulnerabilities may allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial-of-service condition.

US-CERT encourages users to review the changelogchangelog and update to ClamAV 0.93ClamAV 0.93 to help mitigate the risks.