HTTP: ClamAV libclamav PE File Handling Integer Overflow
This signature detects attempts to exploit a known vulnerability in ClamAV Antivirus. A successful attack can lead to a integer overflow and arbitrary remote code execution within the context of the process's user.
Extended Description
ClamAV is prone to a heap-corruption vulnerability and an integer-overflow vulnerability. Successfully exploiting these issues allows remote attackers to execute arbitrary machine code in the context of the affected application. This facilitates the remote compromise of affected computers. Failed exploit attempts likely result in application crashes. Versions prior to ClamAV 0.92.1 are affected by these issues.
Affected Products
Clam_anti-virus clamav
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Red_hat
Suse
Apple
Gentoo
Clam_anti-virus
Mandriva
Debian
Kolab
10.0