Andreas Barth | 12 Dec 22:43

[VUA 24-1] Updated clamav package


---------------------------------------------------------------------------
Debian Volatile Update Announcement VUA 24-1     http://volatile.debian.net
debian-volatile <at> lists.debian.org                   	       Stephen Gran
December 12th, 2006				 Felipe Augusto van de Wiel 
---------------------------------------------------------------------------

Package              : clamav
Version              : 0.88.7-0volatile1
Importance           : high
CVE IDs              : CVE-2006-6406
                       [ not know yet] 

The following security flaws were found and fixed in clamav:

CVE-2006-6406:

    A vulnerabilty has been discovered in clamav's MIME parser that can allow
    a carefully crafted message to bypass scanning.

[ not know yet ]:

    A vulnerability has been discovered in clamav's routines for examining
    nested multipart MIME sections that could be exploited to lead to a Denial
    of service attack.

For sarge, an updated clamav package is available in sarge/volatile
as version 0.88.7-0volatile1. We recommend that you update your system.

This advisory was sent out without builds for arm, m68k, mips, mipsel
(Continue reading)


Gmane