Package: clamav Version: 0.96+dfsg-4~volatile1 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1640
Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV 0.96 allows remote attackers to cause a denial of service (crash) via a crafted PE icon that triggers an out-of-bounds read, related to improper rounding during scaling. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1639 The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length and the real stream length. FIX: New version (0.96.1) contain all fixes of the bugs mentioned above. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org