oss-sec mailing list archives
CVE request: ClamAV vulnerabilities
From: Sergey Popov <pinkbyte () gentoo org>
Date: Fri, 29 Nov 2013 13:20:42 +0400
It's a bit late, but i would like to request CVE for two vulnerabilities, that present in ClamAV before 0.97.7[1]: 1) A double-free error exists within the "unrar_extract_next_prepare()" function (libclamunrar_iface/unrar_iface.c) when parsing a RAR file. 2) An unspecified error within the "wwunpack()" function (libclamav/wwunpack.c) when unpacking a WWPack file can be exploited to corrupt heap memory. [1] - https://secunia.com/advisories/52647/ -- Best regards, Sergey Popov Gentoo developer Gentoo Desktop Effects project lead Gentoo Qt project lead Gentoo Proxy maintainers project lead
Attachment:
signature.asc
Description: OpenPGP digital signature
Current thread:
- CVE request: ClamAV vulnerabilities Sergey Popov (Nov 29)
- Re: CVE request: ClamAV vulnerabilities Kurt Seifried (Nov 29)
- Re: CVE request: ClamAV vulnerabilities George Theall (Nov 29)
- Re: CVE request: ClamAV vulnerabilities Kurt Seifried (Dec 06)
- Re: CVE request: ClamAV vulnerabilities Sergey Popov (Dec 09)
- Re: CVE request: ClamAV vulnerabilities cve-assign (Dec 09)
- Re: CVE request: ClamAV vulnerabilities cve-assign (Dec 11)
- Re: CVE request: ClamAV vulnerabilities cve-assign (Dec 12)
- Re: CVE request: ClamAV vulnerabilities George Theall (Nov 29)
- Re: CVE request: ClamAV vulnerabilities Kurt Seifried (Nov 29)