Bug 1167139 (CVE-2014-9050) - CVE-2014-9050 clamav: heap-based buffer overflow when scanning crypted PE files
Summary: CVE-2014-9050 clamav: heap-based buffer overflow when scanning crypted PE files
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: CVE-2014-9050
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1167140 1167141
Blocks:
TreeView+ depends on / blocked
 
Reported: 2014-11-24 01:01 UTC by Murray McAllister
Modified: 2019-09-29 13:24 UTC (History)
11 users (show)

Fixed In Version: clamav 0.98.5
Clone Of:
Environment:
Last Closed: 2015-06-10 01:36:21 UTC
Embargoed:


Attachments (Terms of Use)

Description Murray McAllister 2014-11-24 01:01:03 UTC
A heap-based buffer overflow flaw was found in ClamAV when scanning Windows PE files that were crypted with y0da's Crypter. Scanning a malicious PE file could cause ClamAV to crash or, potentially, execute arbitrary code.

Upstream fix:

https://github.com/vrtadmin/clamav-devel/commit/fc3794a54d2affe5770c1f876484a871c783e91e

References:
http://seclists.org/oss-sec/2014/q4/752
https://bugzilla.clamav.net/show_bug.cgi?id=11155 (currently private)

Comment 1 Murray McAllister 2014-11-24 01:02:14 UTC
Created clamav tracking bugs for this issue:

Affects: fedora-all [bug 1167140]
Affects: epel-all [bug 1167141]

Comment 2 Robert Scheck 2014-11-24 22:43:48 UTC
Which ClamAV release contains a fix? 0.98.5 already? Or 0.98.6?

Comment 3 Robert Scheck 2014-11-24 22:46:28 UTC
Ah, http://seclists.org/oss-sec/2014/q4/752 answers it (0.98.5 contains a
fix), sorry for the noise.

Comment 4 Fedora Update System 2014-11-27 08:37:34 UTC
clamav-0.98.5-1.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 5 Fedora Update System 2014-12-01 21:43:06 UTC
clamav-0.98.5-1.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2014-12-01 21:44:25 UTC
clamav-0.98.5-1.el6 has been pushed to the Fedora EPEL 6 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 7 Fedora Update System 2014-12-05 01:10:58 UTC
clamav-0.98.5-1.el7 has been pushed to the Fedora EPEL 7 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 8 Fedora Update System 2014-12-06 10:32:21 UTC
clamav-0.98.5-1.fc21 has been pushed to the Fedora 21 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.