Hanno Boeck reported following issue affecting clamav: Description: CERT-FI published an advisory with a large number of samples of crafted archives. The file with the md5sum b6046d890e6bd304e3756c88b989559a (named b6046d890e6bd304e3756c88b989559a.arj) hangs clamav with high load. If you're running clamav on a mailserver, an attacker can DoS your Server remotely by sending some mails with the archive attached. Workaround/Fix: clamav 0.93 fixes this issue beside other security issues, if you're running clamav you should upgrade as soon as possible. References: http://int21.de/cve/CVE-2008-1387-clamav.html https://wwws.clamav.net/bugzilla/show_bug.cgi?id=897 http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLog http://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html
clamav-0.92.1-2.fc7 has been submitted as an update for Fedora 7
clamav-0.92.1-2.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
clamav-0.92.1-2.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
clamav-0.93-1.fc9 has been submitted as an update for Fedora 9
clamav-0.93-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
This issue was addressed in: Fedora: https://admin.fedoraproject.org/updates/F7/FEDORA-2008-3358 https://admin.fedoraproject.org/updates/F8/FEDORA-2008-3420 https://admin.fedoraproject.org/updates/F9/FEDORA-2008-3900