Title : ClamAV Upack Executable Processing Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-1218 CVE ID : CVE-2008-1100
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-14
Technical Description
A vulnerability has been identified in Clam AntiVirus (ClamAV), which could be exploited by remote attackers or malware to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error in the "cli_scanpe()" [libclamav/pe.c] function when processing a specially crafted "Upack" executable, which could be exploited by attackers to execute arbitrary commands by tricking a vulnerable application into scanning a specially crafted file.