HTTP: ClamAV libclamav PE File Handling Integer Overflow

This signature detects attempts to exploit a known vulnerability in ClamAV Antivirus. A successful attack can lead to a integer overflow and arbitrary remote code execution within the context of the process's user.

Extended Description

ClamAV is prone to a heap-corruption vulnerability and an integer-overflow vulnerability. Successfully exploiting these issues allows remote attackers to execute arbitrary machine code in the context of the affected application. This facilitates the remote compromise of affected computers. Failed exploit attempts likely result in application crashes. Versions prior to ClamAV 0.92.1 are affected by these issues.

Affected Products

Clam_anti-virus clamav

References

BugTraq: 27751

CVE: CVE-2008-0318

Short Name
HTTP:STC:DL:CLAMAV-PE-INT
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2008-0318 ClamAV File Handling Integer Overflow PE bid:27751 libclamav
Release Date
09/27/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Red_hat

Suse

Apple

Gentoo

Clam_anti-virus

Mandriva

Debian

Kolab

CVSS Score

10.0

Found a potential security threat?