Common Vulnerabilities and Exposures assigned an identifier CVE-2008-0314 to the following vulnerability: Heap-based buffer overflow in spin.c in libclamav in ClamAV 0.92.1 allows remote attackers to execute arbitrary code via a crafted PeSpin packed PE binary with a modified length value. Fixed in 0.93. References: http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=686 https://wwws.clamav.net/bugzilla/show_bug.cgi?id=876
clamav-0.92.1-2.fc7 has been submitted as an update for Fedora 7
clamav-0.92.1-2.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
clamav-0.92.1-2.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
clamav-0.93-1.fc9 has been submitted as an update for Fedora 9
clamav-0.93-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
This issue was addressed in: Fedora: https://admin.fedoraproject.org/updates/F7/FEDORA-2008-3358 https://admin.fedoraproject.org/updates/F8/FEDORA-2008-3420 https://admin.fedoraproject.org/updates/F9/FEDORA-2008-3900