Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Thu, 20 Nov 2008 19:43:29 -0500 (EST)
From: "Steven M. Christey" <coley@...us.mitre.org>
To: OSS-Security Mailinglist <oss-security@...ts.openwall.com>
cc: coley@...re.org
Subject: Re: CVE request: clamav get_unicode_name() off-by-one
 buffer overflow


======================================================
Name: CVE-2008-5050
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5050
Reference: BUGTRAQ:20081108 ClamAV get_unicode_name() off-by-one buffer overflow
Reference: URL:http://www.securityfocus.com/archive/1/archive/1/498169/100/0/threaded
Reference: FULLDISC:20081109 ClamAV get_unicode_name() off-by-one buffer overflow
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2008-November/065530.html
Reference: CONFIRM:http://sourceforge.net/project/shownotes.php?release_id=637952&group_id=86638
Reference: BID:32207
Reference: URL:http://www.securityfocus.com/bid/32207
Reference: FRSIRT:ADV-2008-3085
Reference: URL:http://www.frsirt.com/english/advisories/2008/3085
Reference: SECUNIA:32663
Reference: URL:http://secunia.com/advisories/32663
Reference: XF:clamav-getunicodename-bo(46462)
Reference: URL:http://xforce.iss.net/xforce/xfdb/46462

Off-by-one error in the get_unicode_name function
(libclamav/vba_extract.c) in Clam Anti-Virus (ClamAV) before 0.94.1
allows remote attackers to cause a denial of service (crash) or
possibly execute arbitrary code via a crafted VBA project file, which
triggers a heap-based buffer overflow.


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.