Bug#523016: clamav vulnerability

2009-04-07 Thread Nico Golde
Hi, nope this is not covered by CVE-2009-1241, new CVE id/s pending. Cheers Nico -- Nico Golde - http://www.ngolde.de - n...@jabber.ccc.de - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted. pgpO0OOoLwceE.pgp Description: PGP signature

Bug#523016: clamav vulnerability

2009-04-07 Thread Michael S. Gilbert
package: clamav severity: grave tags: security hi, ubuntu recently patched a problem in clamav [1]. the description is: It was discovered that ClamAV did not properly verify its input when processing TAR archives. A remote attacker could send a specially crafted TAR file and cause a denia