CVE-2009-1371
published 2009-04-23CVE-2009-1371: The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a…
PriorityP417medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.42%
87.7th percentile
The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.
Affected
101 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| clamav | clamav | <= 0.95 | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-93pj-83f5-xggg: The CLI_ISCONTAINED macro in libclamav/others
ghsa_unreviewed·2022-05-02
CVE-2009-1371 [MEDIUM] CWE-20 GHSA-93pj-83f5-xggg: The CLI_ISCONTAINED macro in libclamav/others
The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.
OSV
CVE-2009-1371: The CLI_ISCONTAINED macro in libclamav/others
osv·2009-04-23·CVSS 5.0
CVE-2009-1371 [MEDIUM] CVE-2009-1371: The CLI_ISCONTAINED macro in libclamav/others
The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.
Debian
CVE-2009-1371: clamav - The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows r...
vendor_debian·2009·CVSS 5.0
CVE-2009-1371 [MEDIUM] CVE-2009-1371: clamav - The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows r...
The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.
Scope: local
bookworm: resolved (fixed in 0.95.1+dfsg-1)
bullseye: resolved (fixed in 0.95.1+dfsg-1)
forky: resolved (fixed in 0.95.1+dfsg-1)
sid: resolved (fixed in 0.95.1+dfsg-1)
trixie: resolved (fixed in 0.95.1+dfsg-1)
Red Hat
clamav: security fixes in upstream 0.95.1 (CVE-2009-1371, CVE-2009-1372)
vendor_redhat·CVSS 5.0
CVE-2009-1371 [MEDIUM] clamav: security fixes in upstream 0.95.1 (CVE-2009-1371, CVE-2009-1372)
clamav: security fixes in upstream 0.95.1 (CVE-2009-1371, CVE-2009-1372)
The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.
Red Hat
clamav: security fixes in upstream 0.95.1 (CVE-2009-1371, CVE-2009-1372)
vendor_redhat·CVSS 5.0
CVE-2009-1372 [MEDIUM] clamav: security fixes in upstream 0.95.1 (CVE-2009-1371, CVE-2009-1372)
clamav: security fixes in upstream 0.95.1 (CVE-2009-1371, CVE-2009-1372)
Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL.
No detection rules found.
No public exploits indexed.
Bugzilla
Clam AntiVirus: Multiple vulnerabilities
bugzilla·2009-09-09·CVSS 5.0
[MEDIUM] Clam AntiVirus: Multiple vulnerabilities
Clam AntiVirus: Multiple vulnerabilities
Personal comment
Probably SELINUX targeted policy, and Selinux Memory check, mitigate this
but it necessary to upgrade anyway. I open here because this is a security bug and not a generic bug.
Synopsis
Multiple vulnerabilities in ClamAV allow for the remote execution of arbitrary code or Denial of Service.
2. Impact Information
Background
Clam AntiVirus (short: ClamAV) is an anti-virus toolkit for UNIX, designed especially for e-mail scanning on mail gateways.
Description
Multiple vulnerabilities have been found in ClamAV:
* The vendor reported a Divide-by-zero error in the PE ("Portable Executable"; Windows .exe) file handling of ClamAV (CVE-2008-6680).
* Jeffrey Thomas Peckham found a flaw in libclamav/untar.c, possibly resulting in an
Bugzilla
clamav: security fixes in upstream 0.95.1 (CVE-2009-1371, CVE-2009-1372)
bugzilla·2009-04-09·CVSS 5.0
CVE-2009-1371 [MEDIUM] clamav: security fixes in upstream 0.95.1 (CVE-2009-1371, CVE-2009-1372)
clamav: security fixes in upstream 0.95.1 (CVE-2009-1371, CVE-2009-1372)
Upstream clamav version 0.95.1 seems to fix two bugs that may cause clamscan / clamd to crash when scanning certain inputs:
Crash when scanning a malformed file packed with UPack
Upstream bug:
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1552
cli_url_canon buffer overflow (this only seems to affect 0.95.x)
Upstream bug:
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1553
Both fixed upstream in:
svn diff -c 5032 http://svn.clamav.net/svn/clamav-devel/
Discussion:
Package: clamav-0.95.1-1.fc11 Tag: dist-f11 Status: complete Built by: robert
1963 (clamav): Build on target fedora-5-epel succeeded.
1965 (clamav): Build on target fedora-4-epel succeeded.
---
CVE-2009-1371:
The CLI_ISCONTAINED macro in lib
http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.htmlhttp://osvdb.org/53602http://secunia.com/advisories/34612http://secunia.com/advisories/34654http://secunia.com/advisories/34716http://secunia.com/advisories/36701http://support.apple.com/kb/HT3865http://svn.clamav.net/websvn/filedetails.php?repname=clamav-devel&path=%2Ftrunk%2FChangeLog&rev=5032http://www.debian.org/security/2009/dsa-1771http://www.mandriva.com/security/advisories?name=MDVSA-2009:097http://www.securityfocus.com/bid/34446http://www.securitytracker.com/id?1022028http://www.ubuntu.com/usn/usn-756-1http://www.vupen.com/english/advisories/2009/0985https://launchpad.net/bugs/360502https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1552http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.htmlhttp://osvdb.org/53602http://secunia.com/advisories/34612http://secunia.com/advisories/34654http://secunia.com/advisories/34716http://secunia.com/advisories/36701http://support.apple.com/kb/HT3865http://svn.clamav.net/websvn/filedetails.php?repname=clamav-devel&path=%2Ftrunk%2FChangeLog&rev=5032http://www.debian.org/security/2009/dsa-1771http://www.mandriva.com/security/advisories?name=MDVSA-2009:097http://www.securityfocus.com/bid/34446http://www.securitytracker.com/id?1022028http://www.ubuntu.com/usn/usn-756-1http://www.vupen.com/english/advisories/2009/0985https://launchpad.net/bugs/360502https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1552
2009-04-23
Published