Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1680-1] New clamav packages fix potential code executio

    From Florian Weimer@1:229/2 to All on Thu Dec 4 09:30:13 2008
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1680-1 [email protected] http://www.debian.org/security/ Florian Weimer December 04, 2008 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : clamav
    Vulnerability : buffer overflow, stack consumption
    Problem type : local (remote)
    Debian-specific: no
    CVE Id(s) : CVE-2008-5050 CVE-2008-5314
    Debian Bug : 505134 507624

    Moritz Jodeit discovered that ClamAV, an anti-virus solution, suffers
    from an off-by-one-error in its VBA project file processing, leading to
    a heap-based buffer overflow and potentially arbitrary code execution (CVE-2008-5050).

    Ilja van Sprundel discovered that ClamAV contains a denial of service
    condition in its JPEG file processing because it does not limit the
    recursion depth when processing JPEG thumbnails (CVE-2008-5314).

    For the stable distribution (etch), these problems have been fixed in
    version 0.90.1dfsg-4etch16.

    For the unstable distribution (sid), these problems have been fixed in
    version 0.94.dfsg.2-1.

    The testing distribution (lenny) will be fixed soon.

    We recommend that you upgrade your clamav packages.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 4.0 alias etch
    - -------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1dfsg.orig.tar.gz
    Size/MD5 checksum: 11610428 6dc18602b0aa653924d47316f9411e49
    http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1dfsg-4etch16.dsc
    Size/MD5 checksum: 908 ebc60299a69aab41dfdb77e667e2857c
    http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1dfsg-4etch16.diff.gz
    Size/MD5 checksum: 216130 5ae1da1b6351a13b5c385919960ca9b7

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/c/clamav/clamav-base_0.90.1dfsg-4etch16_all.deb
    Size/MD5 checksum: 201408 63e3898029276baf914fafa347747996
    http://security.debian.org/pool/updates/main/c/clamav/clamav-docs_0.90.1dfsg-4etch16_all.deb
    Size/MD5 checksum: 1003722 5d316f2ea821b441971b0e05e58e481d
    http://security.debian.org/pool/updates/main/c/clamav/clamav-testfiles_0.90.1dfsg-4etch16_all.deb
    Size/MD5 checksum: 158564 189a55ca25bdf9e03a0ae3b9f4a565e9

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1dfsg-4etch16_alpha.deb
    Size/MD5 checksum: 373052 b59a6787be52e776d3b6238bac4e7fff
    http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1dfsg-4etch16_alpha.deb
    Size/MD5 checksum: 182812 289769066d1883af6c455255725c1c81
    http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1dfsg-4etch16_alpha.deb
    Size/MD5 checksum: 9305338 e2d5290afa1484ffc3ee6abfc99a7e5f
    http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1dfsg-4etch16_alpha.deb
    Size/MD5 checksum: 465410 ad42ee7f6355353575f05de54d67fa2b
    http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1dfsg-4etch16_alpha.deb
    Size/MD5 checksum: 598714 6f862583fe87d09e3c3a3c288c75a787
    http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1dfsg-4etch16_alpha.deb
    Size/MD5 checksum: 180954 7122cfc98ec69b5b012d9794dc3f44cd
    http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1dfsg-4etch16_alpha.deb
    Size/MD5 checksum: 862390 df3cb4e88d62cbc641d1c48c14d5c551

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1dfsg-4etch16_amd64.deb
    Size/MD5 checksum: 856672 bc8b467814eb5b76b6a165ee7abbbb7d
    http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1dfsg-4etch16_amd64.deb
    Size/MD5 checksum: 177968 c2aa51b550584931f3f1b7b1f6df6508
    http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1dfsg-4etch16_amd64.deb
    Size/MD5 checksum: 9302094 cd9f623cfb4f23d1777cf21e830d74b2
    http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1dfsg-4etch16_amd64.deb
    Size/MD5 checksum: 355706 e0db968192096ac9215ab676b5750c7d
    http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1dfsg-4etch16_amd64.deb
    Size/MD5 checksum: 179200 99ba1e041488e76a7d6e457ed51536f0
    http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1dfsg-4etch16_amd64.deb
    Size/MD5 checksum: 341684 6207bf783731c636eaa192d696466a88
    http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1dfsg-4etch16_amd64.deb
    Size/MD5 checksum: 594608 5e87c000b193a1d25e03580496b91fc2

    hppa architecture (HP PA RISC)

    http://security.debian.org/pool/updates/main/c/clamav/clamav-milter_0.90.1dfsg-4etch16_hppa.deb
    Size/MD5 checksum: 178252 a2dadc8689fd265609265d65f9ba5cf7
    http://security.debian.org/pool/updates/main/c/clamav/clamav-daemon_0.90.1dfsg-4etch16_hppa.deb
    Size/MD5 checksum: 178500 e26b37f74b35c6128654305c2d8f68eb
    http://security.debian.org/pool/updates/main/c/clamav/libclamav2_0.90.1dfsg-4etch16_hppa.deb
    Size/MD5 checksum: 373174 c8815805d7a9cf555a1611b7314cbe93
    http://security.debian.org/pool/updates/main/c/clamav/clamav-dbg_0.90.1dfsg-4etch16_hppa.deb
    Size/MD5 checksum: 573090 724ad2d96fcd7b80e7a1c8c090fb9b04
    http://security.debian.org/pool/updates/main/c/clamav/clamav-freshclam_0.90.1dfsg-4etch16_hppa.deb
    Size/MD5 checksum: 9303992 c463499f12992880b420a015b1bd5d9a
    http://security.debian.org/pool/updates/main/c/clamav/clamav_0.90.1dfsg-4etch16_hppa.deb
    Size/MD5 checksum: 857738 1ebd69a77c29a7fc69f02b27b2dad3e6
    http://security.debian.org/pool/updates/main/c/clamav/libclamav-dev_0.90.1dfsg-4etch16_hppa.deb
    Size/MD5 checksum: 396534 d889914674f27507e6ca759d78d22995

    i386 architecture (Intel ia32)


    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Krenn
      Tue Jun 9 11:18:15 2026
      from Sydney, Nsw via Telnet
    • Bob Worm
      Tue Jun 9 10:31:07 2026
      from Wales, Uk via Telnet
    • Centurion
      Mon Jun 8 23:30:43 2026
      from Berea, Ohio via Telnet
    • Centurion
      Mon Jun 8 21:33:11 2026
      from Berea, Ohio via Telnet
    • Bob Worm
      Mon Jun 8 20:15:00 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 16:33:22 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 14:11:46 2026
      from Wales, Uk via Telnet
    • Krenn
      Mon Jun 8 11:22:02 2026
      from Sydney, Nsw via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (3 / 13)
    Uptime: 43:05:49
    Calls: 12,111
    Calls today: 2
    Files: 15,008
    Messages: 6,518,438

© >>> Magnum BBS <<<, 2026