<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-12607</id>
	<title>Nabble - openbsd user - ports-security</title>
	<updated>2006-01-13T15:35:03Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/openbsd-user---ports-security-f12607.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/openbsd-user---ports-security-f12607.html" />
	<subtitle type="html">Security announcements for ports and packages. This low volume list receives OpenBSD security advisories concerning the ports tree and packages with more information about the vulnerabilities and patches.</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-2372210</id>
	<title>OPSA_20060114: clamav -- heap overflow in the UPX code</title>
	<published>2006-01-13T15:35:03Z</published>
	<updated>2006-01-13T15:35:03Z</updated>
	<author>
		<name>Robert Nagy</name>
	</author>
	<content type="html">+--------------------------------------------------------------------------
&lt;br&gt;| OpenBSD Package Security Advisory &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; OPSA 20060114-0
&lt;br&gt;+--------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;Short description
&lt;br&gt;-----------------
&lt;br&gt;clamav -- heap overflow in the UPX code
&lt;br&gt;&lt;br&gt;Affected packages linked to affected branches
&lt;br&gt;---------------------------------------------
&lt;br&gt;clamav &amp;lt; 0.88	----------&amp;gt; HEAD (OpenBSD -current)
&lt;br&gt;clamav &amp;lt; 0.88	----------&amp;gt; OPENBSD_3_8 (OpenBSD 3.8)
&lt;br&gt;clamav &amp;lt; 0.88	----------&amp;gt; OPENBSD_3_7 (OpenBSD 3.7)
&lt;br&gt;&lt;br&gt;Detailed description
&lt;br&gt;--------------------
&lt;br&gt;A vulnerability has been reported in ClamAV,
&lt;br&gt;which potentially can be exploited by malicious
&lt;br&gt;people with an unknown impact.
&lt;br&gt;The vulnerability is caused due to an unspecified
&lt;br&gt;boundary error in &amp;quot;libclamav/upx.c&amp;quot;.
&lt;br&gt;This can potentially be exploited to cause a heap-based
&lt;br&gt;buffer overflow via a specially-crafted UPX packed file.
&lt;br&gt;&lt;br&gt;References
&lt;br&gt;----------
&lt;br&gt;&lt;a href=&quot;http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0162&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0162&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/18379&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/18379&lt;/a&gt;&lt;br&gt;&lt;br&gt;Solution
&lt;br&gt;--------
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;a) You can update your ports tree via CVS described at
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openbsd.org/ports.html#stable&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openbsd.org/ports.html#stable&lt;/a&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Then you can recompile the port and reinstall it.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; (Please be careful to use the correct CVS branch)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp;b) You can install the fixed package from our FTP servers
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; $ pkg_add -r ftp://ftp.openbsd.org/\
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pub/OpenBSD/3.8/packages/i386/clamav-0.88.tgz
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; (Please be careful to use the correct release.)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; (Note: We only provide fixed packages for i386.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;You will need to recompile from the ports tree
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;if you use a different architecture.)
&lt;br&gt;&lt;br&gt;+---------------------------------------------------------------------------
&lt;br&gt;| If you have any problem, feel free to write to the OpenBSD ports mailing
&lt;br&gt;| list. Please visit &lt;a href=&quot;http://www.openbsd.org/mail.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openbsd.org/mail.html&lt;/a&gt;&amp;nbsp;for more information
&lt;br&gt;| about our mailing lists.
&lt;br&gt;+---------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OPSA_20060114%3A-clamav----heap-overflow-in-the-UPX-code-tp2372210p2372210.html" />
</entry>

</feed>
