CVE-2008-1100

Publication date 14 April 2008

Last updated 24 July 2024


Ubuntu priority

Buffer overflow in the cli_scanpe function in libclamav (libclamav/pe.c) for ClamAV 0.92 and 0.92.1 allows remote attackers to execute arbitrary code via a crafted Upack PE file.

Read the notes from the security team

Status

Package Ubuntu Release Status
clamav 8.04 LTS hardy
Fixed 0.92.1~dfsg2-1
7.10 gutsy
Fixed 0.92.1~dfsg2-1.1~gutsy2
7.04 feisty
Fixed 0.92.1~dfsg2-1.1~feisty2
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper
Fixed 0.92.1~dfsg2-1.1~dapper2

Notes


jdstrand

debdiff is for SRU of dapper to dapper-backports

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
clamav