[Bug 298637] [NEW] CVE-2008-5050: heap overflow vulnerability in the code responsible for parsing VBA project files

Launchpad Bug Tracker 298637 at bugs.launchpad.net
Mon Nov 17 15:09:49 UTC 2008


*** This bug is a security vulnerability ***

You have been subscribed to a public security bug by Jamie Strandboge (jdstrand):

Binary package hint: clamav

Reference :

  http://seclists.org/bugtraq/2008/Nov/0070.html

Patch:

  http://svn.clamav.net/websvn/diff.php?repname=clamav-
devel&path=/trunk/libclamav/vba_extract.c&rev=4311

Impact:

  remotely exploitable if using clamav as a mail scanner in intrepid

** Affects: clamav (Ubuntu)
     Importance: Undecided
         Status: New

** Affects: debian
     Importance: Unknown
         Status: Unknown

** Affects: clamav (Fedora)
     Importance: Unknown
         Status: Confirmed

** Affects: clamav (Gentoo Linux)
     Importance: Unknown
         Status: In Progress

-- 
CVE-2008-5050: heap overflow vulnerability in the code responsible for parsing VBA project files
https://bugs.launchpad.net/bugs/298637
You received this bug notification because you are a member of Ubuntu Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs at lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs




More information about the universe-bugs mailing list