Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an out-of-bounds read.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ubuntu_linux | Canonical | 10.04 (including) | 10.04 (including) |
Ubuntu_linux | Canonical | 11.10 (including) | 11.10 (including) |
Ubuntu_linux | Canonical | 12.04 (including) | 12.04 (including) |
Ubuntu_linux | Canonical | 12.10 (including) | 12.10 (including) |
Ubuntu_linux | Canonical | 13.04 (including) | 13.04 (including) |
Clamav | Ubuntu | devel | * |
Clamav | Ubuntu | hardy | * |
Clamav | Ubuntu | lucid | * |
Clamav | Ubuntu | oneiric | * |
Clamav | Ubuntu | precise | * |
Clamav | Ubuntu | quantal | * |
Clamav | Ubuntu | raring | * |
Clamav | Ubuntu | upstream | * |