ClamAV.UPX.Heap.Buffer.Overflow

description-logoDescription

This indicates an attack attempt against a heap-based buffer-overflow vulnerability in Clam AntiVirus.
The vulnerability exists in the pefromupx function in libclamav/upx.c. It is caused by insufficient checking of user-supplied input before the vulnerable software copies it to an insufficient buffer. It allows a remote attacker to execute arbitrary code via sending a crafted UPX packed file.

affected-products-logoAffected Products

Clam AntiVirus 0.8.8.2
Clam AntiVirus 0.8.8.3

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Upgrade the Clam AntiVirus.
http://www.clamav.net/

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)