Buffer overflow in ClamAV - CVE-2014-9328
Published: February 3, 2015 / Updated: July 28, 2020
Vulnerability identifier: #VU32441
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-9328
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upack packer file, related to a "heap out of bounds condition."
Affected software
ClamAV
Amazon Linux AMI
Fedora
SUSE Linux
clamav (Alpine package)
clamav
Amazon Linux AMI
Fedora
SUSE Linux
clamav (Alpine package)
clamav
How to mitigate CVE-2014-9328
Install update from vendor's website.
ClamAV - update to 0.98.6
clamav (Alpine package) - update to 0.98.6-r0
clamav - addressed in versions 0.98.6-1.el5, 0.98.6-1.el6, 0.98.6-1.el7, 0.98.6-1.fc21
clamav (Alpine package) - update to 0.98.6-r0
clamav - addressed in versions 0.98.6-1.el5, 0.98.6-1.el6, 0.98.6-1.el7, 0.98.6-1.fc21
External References
- http://blog.clamav.net/2015/01/clamav-0986-has-been-released.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-January/148950.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-January/148958.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00020.html
- http://lists.opensuse.org/opensuse-updates/2015-05/msg00024.html
- http://secunia.com/advisories/62536
- http://secunia.com/advisories/62757
- http://securitytracker.com/id/1031672
- http://www.securityfocus.com/bid/72372
- http://www.ubuntu.com/usn/USN-2488-2
- https://security.gentoo.org/glsa/201512-08