[Full-disclosure] clamav: Crash with crafted chm, CVE-2008-1389
- From: Hanno Böck <hanno@xxxxxxxxx>
- Date: Thu, 4 Sep 2008 16:03:25 +0200
clamav: Crash with crafted chm, CVE-2008-1389
A fuzzing test showed weakness in the chm parser of clamav, which can possibly
The clamav team has disabled the chm module in older versions though freshclam
updates and has released 0.94 with a fixed parser.
The clamav team has not mentioned this issue in the release notes of 0.94,
which is very bad security behaviour.
2008-07-09: clamav bug opened
unknown date: clamav disables chm-parser through freshclam
2008-09-02 Vendor releases 0.94
2008-09-04 Released this advisory
The Common Vulnerabilities and Exposures (CVE) project has assigned the name
CVE-2008-1389 to this issue. This is a candidate for inclusion in the CVE
list (http://cve.mitre.org/), which standardizes names for security problems.
Credits and copyright
This vulnerability was discovered by Hanno Boeck of schokokeks.org webhosting.
It's licensed under the creative commons attribution license.
Hanno Boeck, 2008-09-04, http://www.hboeck.de
Hanno Böck Blog: http://www.hboeck.de/
GPG: 3DBD3B20 Jabber/Mail: hanno@xxxxxxxxx
Description: This is a digitally signed message part.
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/
- Prev by Date: Re: [Full-disclosure] Google Chrome Browser Vulnerability
- Next by Date: Re: [Full-disclosure] Hardcoded Keys
- Previous by thread: [Full-disclosure] Multiple Cross Site Scripting (XSS) and SQL injection Vulnerabilities in XRMS, CVE-2008-3664
- Next by thread: [Full-disclosure] [ GLSA 200809-01 ] yelp: User-assisted execution of arbitrary code