Integer overflow in the cli_scanpe function in libclamav in ClamAV before 0.92.1, as used in clamd, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Petite packed PE file, which triggers a heap-based buffer overflow.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Clamav | Clam_anti-virus | * | 0.92 (including) |
Clamav | Ubuntu | dapper | * |
Clamav | Ubuntu | devel | * |
Clamav | Ubuntu | edgy | * |
Clamav | Ubuntu | feisty | * |
Clamav | Ubuntu | gutsy | * |
Clamav | Ubuntu | upstream | * |