Clam Anti-Virus CHM解包器拒绝服务漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

Clam AntiVirus是Unix的GPL杀毒工具包,很多邮件网关产品都在使用。 ClamAV在处理CHM文件的解包时存在安全漏洞,远程攻击者可能利用此漏洞导致ClamAV崩溃。 在处理畸形文件时,ClamAV chmunpack.c中的代码可能试图读取无效的内存位置,导致扫描服务异常终止。 ClamAV ClamAV 0.88.4 厂商补丁: Debian ------ Debian已经为此发布了一个安全公告(DSA-1196-1)以及相应补丁: DSA-1196-1:New clamav packages fix arbitrary code execution 链接:http://www.debian.org/security/2005/dsa-1196 补丁下载: Source archives: http://security.debian.org/pool/updates/main/c/clamav/clamav_0.84-2.sarge.11.dsc Size/MD5 checksum: 874 28ac6ad45d008a1a40f1043ce208f7e9 http://security.debian.org/pool/updates/main/c/clamav/clamav_0.84-2.sarge.11.diff.gz Size/MD5 checksum: 176562 4b0c191cf10e3184baee4004c7992b09 http://security.debian.org/pool/updates/main/c/clamav/clamav_0.84.orig.tar.gz Size/MD5 checksum: 4006624 c43213da01d510faf117daa9a4d5326c Architecture independent components: http://security.debian.org/pool/updates/main/c/clamav/clamav-base_0.84-2.sarge.11_all.deb Size/MD5 checksum: 154890 32b1629d649ed6168dd411e0458cca08...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息