CVE-2005-3229

Publication date 14 October 2005

Last updated 24 July 2024


Ubuntu priority

Multiple interpretation error in unspecified versions of ClamAV Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

Read the notes from the security team

Status

Package Ubuntu Release Status
clamav 9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Fixed 0.94.dfsg.2-1ubuntu0.3~hardy4
7.10 gutsy Ignored end of life, was needed
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper
Fixed 0.94.dfsg.2-1ubuntu0.3~dapper2

Notes


jdstrand

clamav no longer has RAR support as of Intrepid