Bugraq ID: 34818 CNCAN ID:CNCAN-2009050603 ClamAV是一款基于unix下的反病毒应用程序。 ClamAV 'clamav-milter' Initscript文件权限设置存在问题,本地攻击者可以利用漏洞进行拒绝服务攻击。 攻击者可以利用漏洞修改部分目录下的文件,导致影响系统完整性并对系统进行进一步攻击。 Clam Anti-Virus ClamAV 0.95.1 厂商解决方案 Ubuntu系统用户可参考如下升级程序: Ubuntu Ubuntu Linux 9.04 amd64 Ubuntu clamav-dbg_0.95.1+dfsg-1ubuntu1.2_amd64.deb <a href=http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-dbg_0.95.1 target=_blank rel=external nofollow>http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-dbg_0.95.1</a> +dfsg-1ubuntu1.2_amd64.deb Ubuntu clamav-docs_0.95.1+dfsg-1ubuntu1.2_all.deb <a href=http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-docs_0.95. target=_blank rel=external nofollow>http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-docs_0.95.</a> 1+dfsg-1ubuntu1.2_all.deb Ubuntu clamav-freshclam_0.95.1+dfsg-1ubuntu1.2_amd64.deb <a href=http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-freshclam_ target=_blank rel=external...
Bugraq ID: 34818 CNCAN ID:CNCAN-2009050603 ClamAV是一款基于unix下的反病毒应用程序。 ClamAV 'clamav-milter' Initscript文件权限设置存在问题,本地攻击者可以利用漏洞进行拒绝服务攻击。 攻击者可以利用漏洞修改部分目录下的文件,导致影响系统完整性并对系统进行进一步攻击。 Clam Anti-Virus ClamAV 0.95.1 厂商解决方案 Ubuntu系统用户可参考如下升级程序: Ubuntu Ubuntu Linux 9.04 amd64 Ubuntu clamav-dbg_0.95.1+dfsg-1ubuntu1.2_amd64.deb <a href=http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-dbg_0.95.1 target=_blank rel=external nofollow>http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-dbg_0.95.1</a> +dfsg-1ubuntu1.2_amd64.deb Ubuntu clamav-docs_0.95.1+dfsg-1ubuntu1.2_all.deb <a href=http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-docs_0.95. target=_blank rel=external nofollow>http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-docs_0.95.</a> 1+dfsg-1ubuntu1.2_all.deb Ubuntu clamav-freshclam_0.95.1+dfsg-1ubuntu1.2_amd64.deb <a href=http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-freshclam_ target=_blank rel=external nofollow>http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-freshclam_</a> 0.95.1+dfsg-1ubuntu1.2_amd64.deb Ubuntu clamav-milter_0.95.1+dfsg-1ubuntu1.2_amd64.deb <a href=http://security.ubuntu.com/ubuntu/pool/universe/c/clamav/clamav-milter target=_blank rel=external nofollow>http://security.ubuntu.com/ubuntu/pool/universe/c/clamav/clamav-milter</a> _0.95.1+dfsg-1ubuntu1.2_amd64.deb Ubuntu clamav_0.95.1+dfsg-1ubuntu1.2_amd64.deb <a href=http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav_0.95.1+dfs target=_blank rel=external nofollow>http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav_0.95.1+dfs</a> g-1ubuntu1.2_amd64.deb Ubuntu libclamav-dev_0.95.1+dfsg-1ubuntu1.2_amd64.deb <a href=http://security.ubuntu.com/ubuntu/pool/main/c/clamav/libclamav-dev_0.9 target=_blank rel=external nofollow>http://security.ubuntu.com/ubuntu/pool/main/c/clamav/libclamav-dev_0.9</a> 5.1+dfsg-1ubuntu1.2_amd64.deb Ubuntu libclamav6_0.95.1+dfsg-1ubuntu1.2_amd64.deb <a href=http://security.ubuntu.com/ubuntu/pool/main/c/clamav/libclamav6_0.95.1 target=_blank rel=external nofollow>http://security.ubuntu.com/ubuntu/pool/main/c/clamav/libclamav6_0.95.1</a> +dfsg-1ubuntu1.2_amd64.deb Ubuntu Ubuntu Linux 9.04 lpia Ubuntu clamav-dbg_0.95.1+dfsg-1ubuntu1.2_lpia.deb <a href=http://ports.ubuntu.com/pool/main/c/clamav/clamav-dbg_0.95.1+dfsg-1ubu target=_blank rel=external nofollow>http://ports.ubuntu.com/pool/main/c/clamav/clamav-dbg_0.95.1+dfsg-1ubu</a> ntu1.2_lpia.deb Ubuntu clamav-docs_0.95.1+dfsg-1ubuntu1.2_all.deb <a href=http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-docs_0.95. target=_blank rel=external nofollow>http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-docs_0.95.</a> 1+dfsg-1ubuntu1.2_all.deb Ubuntu clamav-freshclam_0.95.1+dfsg-1ubuntu1.2_lpia.deb <a href=http://ports.ubuntu.com/pool/main/c/clamav/clamav-freshclam_0.95.1+dfs target=_blank rel=external nofollow>http://ports.ubuntu.com/pool/main/c/clamav/clamav-freshclam_0.95.1+dfs</a> g-1ubuntu1.2_lpia.deb Ubuntu clamav-milter_0.95.1+dfsg-1ubuntu1.2_lpia.deb <a href=http://ports.ubuntu.com/pool/universe/c/clamav/clamav-milter_0.95.1+df target=_blank rel=external nofollow>http://ports.ubuntu.com/pool/universe/c/clamav/clamav-milter_0.95.1+df</a> sg-1ubuntu1.2_lpia.deb Ubuntu clamav_0.95.1+dfsg-1ubuntu1.2_lpia.deb <a href=http://ports.ubuntu.com/pool/main/c/clamav/clamav_0.95.1+dfsg-1ubuntu1 target=_blank rel=external nofollow>http://ports.ubuntu.com/pool/main/c/clamav/clamav_0.95.1+dfsg-1ubuntu1</a> .2_lpia.deb Ubuntu libclamav-dev_0.95.1+dfsg-1ubuntu1.2_lpia.deb <a href=http://ports.ubuntu.com/pool/main/c/clamav/libclamav-dev_0.95.1+dfsg-1 target=_blank rel=external nofollow>http://ports.ubuntu.com/pool/main/c/clamav/libclamav-dev_0.95.1+dfsg-1</a> ubuntu1.2_lpia.deb Ubuntu libclamav6_0.95.1+dfsg-1ubuntu1.2_lpia.deb <a href=http://ports.ubuntu.com/pool/main/c/clamav/libclamav6_0.95.1+dfsg-1ubu target=_blank rel=external nofollow>http://ports.ubuntu.com/pool/main/c/clamav/libclamav6_0.95.1+dfsg-1ubu</a> ntu1.2_lpia.deb Ubuntu Ubuntu Linux 9.04 sparc Ubuntu clamav-dbg_0.95.1+dfsg-1ubuntu1.2_sparc.deb <a href=http://ports.ubuntu.com/pool/main/c/clamav/clamav-dbg_0.95.1+dfsg-1ubu target=_blank rel=external nofollow>http://ports.ubuntu.com/pool/main/c/clamav/clamav-dbg_0.95.1+dfsg-1ubu</a> ntu1.2_sparc.deb Ubuntu clamav-docs_0.95.1+dfsg-1ubuntu1.2_all.deb <a href=http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-docs_0.95. target=_blank rel=external nofollow>http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-docs_0.95.</a> 1+dfsg-1ubuntu1.2_all.deb Ubuntu clamav-freshclam_0.95.1+dfsg-1ubuntu1.2_sparc.deb <a href=http://ports.ubuntu.com/pool/main/c/clamav/clamav-freshclam_0.95.1+dfs target=_blank rel=external nofollow>http://ports.ubuntu.com/pool/main/c/clamav/clamav-freshclam_0.95.1+dfs</a> g-1ubuntu1.2_sparc.deb Ubuntu clamav-milter_0.95.1+dfsg-1ubuntu1.2_sparc.deb <a href=http://ports.ubuntu.com/pool/universe/c/clamav/clamav-milter_0.95.1+df target=_blank rel=external nofollow>http://ports.ubuntu.com/pool/universe/c/clamav/clamav-milter_0.95.1+df</a> sg-1ubuntu1.2_sparc.deb Ubuntu clamav_0.95.1+dfsg-1ubuntu1.2_sparc.deb <a href=http://ports.ubuntu.com/pool/main/c/clamav/clamav_0.95.1+dfsg-1ubuntu1 target=_blank rel=external nofollow>http://ports.ubuntu.com/pool/main/c/clamav/clamav_0.95.1+dfsg-1ubuntu1</a> .2_sparc.deb Ubuntu libclamav-dev_0.95.1+dfsg-1ubuntu1.2_sparc.deb <a href=http://ports.ubuntu.com/pool/main/c/clamav/libclamav-dev_0.95.1+dfsg-1 target=_blank rel=external nofollow>http://ports.ubuntu.com/pool/main/c/clamav/libclamav-dev_0.95.1+dfsg-1</a> ubuntu1.2_sparc.deb Ubuntu libclamav6_0.95.1+dfsg-1ubuntu1.2_sparc.deb <a href=http://ports.ubuntu.com/pool/main/c/clamav/libclamav6_0.95.1+dfsg-1ubu target=_blank rel=external nofollow>http://ports.ubuntu.com/pool/main/c/clamav/libclamav6_0.95.1+dfsg-1ubu</a> ntu1.2_sparc.deb Ubuntu Ubuntu Linux 9.04 powerpc Ubuntu clamav-dbg_0.95.1+dfsg-1ubuntu1.2_powerpc.deb <a href=http://ports.ubuntu.com/pool/main/c/clamav/clamav-dbg_0.95.1+dfsg-1ubu target=_blank rel=external nofollow>http://ports.ubuntu.com/pool/main/c/clamav/clamav-dbg_0.95.1+dfsg-1ubu</a> ntu1.2_powerpc.deb Ubuntu clamav-docs_0.95.1+dfsg-1ubuntu1.2_all.deb <a href=http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-docs_0.95. target=_blank rel=external nofollow>http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-docs_0.95.</a> 1+dfsg-1ubuntu1.2_all.deb Ubuntu clamav-freshclam_0.95.1+dfsg-1ubuntu1.2_powerpc.deb <a href=http://ports.ubuntu.com/pool/main/c/clamav/clamav-freshclam_0.95.1+dfs target=_blank rel=external nofollow>http://ports.ubuntu.com/pool/main/c/clamav/clamav-freshclam_0.95.1+dfs</a> g-1ubuntu1.2_powerpc.deb Ubuntu clamav-milter_0.95.1+dfsg-1ubuntu1.2_powerpc.deb <a href=http://ports.ubuntu.com/pool/universe/c/clamav/clamav-milter_0.95.1+df target=_blank rel=external nofollow>http://ports.ubuntu.com/pool/universe/c/clamav/clamav-milter_0.95.1+df</a> sg-1ubuntu1.2_powerpc.deb Ubuntu clamav_0.95.1+dfsg-1ubuntu1.2_powerpc.deb <a href=http://ports.ubuntu.com/pool/main/c/clamav/clamav_0.95.1+dfsg-1ubuntu1 target=_blank rel=external nofollow>http://ports.ubuntu.com/pool/main/c/clamav/clamav_0.95.1+dfsg-1ubuntu1</a> .2_powerpc.deb Ubuntu libclamav-dev_0.95.1+dfsg-1ubuntu1.2_powerpc.deb <a href=http://ports.ubuntu.com/pool/main/c/clamav/libclamav-dev_0.95.1+dfsg-1 target=_blank rel=external nofollow>http://ports.ubuntu.com/pool/main/c/clamav/libclamav-dev_0.95.1+dfsg-1</a> ubuntu1.2_powerpc.deb Ubuntu libclamav6_0.95.1+dfsg-1ubuntu1.2_powerpc.deb <a href=http://ports.ubuntu.com/pool/main/c/clamav/libclamav6_0.95.1+dfsg-1ubu target=_blank rel=external nofollow>http://ports.ubuntu.com/pool/main/c/clamav/libclamav6_0.95.1+dfsg-1ubu</a> ntu1.2_powerpc.deb Ubuntu Ubuntu Linux 9.04 i386 Ubuntu clamav-dbg_0.95.1+dfsg-1ubuntu1.2_i386.deb <a href=http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-dbg_0.95.1 target=_blank rel=external nofollow>http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-dbg_0.95.1</a> +dfsg-1ubuntu1.2_i386.deb Ubuntu clamav-docs_0.95.1+dfsg-1ubuntu1.2_all.deb <a href=http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-docs_0.95. target=_blank rel=external nofollow>http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-docs_0.95.</a> 1+dfsg-1ubuntu1.2_all.deb Ubuntu clamav-freshclam_0.95.1+dfsg-1ubuntu1.2_i386.deb <a href=http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-freshclam_ target=_blank rel=external nofollow>http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav-freshclam_</a> 0.95.1+dfsg-1ubuntu1.2_i386.deb Ubuntu clamav-milter_0.95.1+dfsg-1ubuntu1.2_i386.deb <a href=http://security.ubuntu.com/ubuntu/pool/universe/c/clamav/clamav-milter target=_blank rel=external nofollow>http://security.ubuntu.com/ubuntu/pool/universe/c/clamav/clamav-milter</a> _0.95.1+dfsg-1ubuntu1.2_i386.deb Ubuntu clamav_0.95.1+dfsg-1ubuntu1.2_i386.deb <a href=http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav_0.95.1+dfs target=_blank rel=external nofollow>http://security.ubuntu.com/ubuntu/pool/main/c/clamav/clamav_0.95.1+dfs</a> g-1ubuntu1.2_i386.deb Ubuntu libclamav-dev_0.95.1+dfsg-1ubuntu1.2_i386.deb <a href=http://security.ubuntu.com/ubuntu/pool/main/c/clamav/libclamav-dev_0.9 target=_blank rel=external nofollow>http://security.ubuntu.com/ubuntu/pool/main/c/clamav/libclamav-dev_0.9</a> 5.1+dfsg-1ubuntu1.2_i386.deb Ubuntu libclamav6_0.95.1+dfsg-1ubuntu1.2_i386.deb <a href=http://security.ubuntu.com/ubuntu/pool/main/c/clamav/libclamav6_0.95.1 target=_blank rel=external nofollow>http://security.ubuntu.com/ubuntu/pool/main/c/clamav/libclamav6_0.95.1</a> +dfsg-1ubuntu1.2_i386.deb