Common Vulnerabilities and Exposures assigned an identifier CVE-2008-1836 to the following vulnerability: The rfc2231 function in message.c in libclamav in ClamAV before 0.93 allows remote attackers to cause a denial of service (crash) via a crafted message that produces a string that is not null terminated, which triggers a buffer over-read. Fixed in 0.93. References: https://wwws.clamav.net/bugzilla/show_bug.cgi?id=881
This issue did not affect clamav-0.92.1, as affected code was introduced in later revisions. clamav-0.93rc1 in Rawhide was affected by this problem.
clamav-0.93-1.fc9 has been submitted as an update for Fedora 9
clamav-0.93-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
This issue was addressed in: Fedora: https://admin.fedoraproject.org/updates/F9/FEDORA-2008-3900