Clam AntiVirus is prone to a format string vulnerability when logging e-mail addresses. This may be exploited to overwrite arbitrary locations in memory with attacker-supplied values, resulting in execution of arbitrary code. This issue only affects the clamav-milter component of versions later than clamav-0.54, which include syslogging functionality.
Clam AntiVirus is prone to a format string vulnerability when logging e-mail addresses. This may be exploited to overwrite arbitrary locations in memory with attacker-supplied values, resulting in execution of arbitrary code. This issue only affects the clamav-milter component of versions later than clamav-0.54, which include syslogging functionality.