A number of potential remote DOS vulnerabilities have been identified in ClamAV. These issues could allow a carefully crafted message to crash a ClamAV scanner or exhaust various resources on the machine running the scanner. Fixed packages are available from .
Debian Security Advisory DSA 737-1                                     Michael Stone
July 05, 2005               
Package        : clamav
Vulnerability  : various DOS vulnerabilities
Problem type   : remote DOS
Debian-specific: no
CVE Id(s)      : CAN-2005-1922, CAN-2005-1923, CAN-2005-2056, CAN-2005-2070

A number of potential remote DOS vulnerabilities have been identified in
ClamAV. In addition to the four issues identified by CVE ID above, there
are fixes for issues in libclamav/cvd.c and libclamav/message.c.
Together, these issues could allow a carefully crafted message to crash
a ClamAV scanner or exhaust various resources on the machine running the

For the stable distribution (sarge), these problems have been fixed in
version 0.84-2.sarge.1.

We recommend that you upgrade your clamav package.

Upgrade instructions
wget url
       will fetch the file for you
dpkg -i file.deb
       will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
       will update the internal database
apt-get upgrade
       will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian 3.1 (sarge)
 Sarge was released for alpha, arm, hppa, i386, ia64, m68k, mips, mipsel, powerpc, s390 and sparc.

For apt-get: deb stable/updates main
For dpkg-ftp: dists/stable/updates/main
Mailing list:
Package info: `apt-cache show ' and
