Security Focus covers a set of ClamAV vulnerabilities, as well as
PHPMyAdmin vulnerabilities:
ClamAV is prone to multiple vulnerabilities. These issues include:
- An integer overflow vulnerability. This issue may permit the execution of
arbitrary code. This can facilitate a compromise of an affected computer.
- A format string vulnerability. This issue may permit the execution of
arbitrary code. This can facilitate a compromise of an affected computer.
- A denial-of-service vulnerability. This issue can be exploited to crash
the affected application. This may aid an attacker in further attacks if
the antivirus software is no longer operational.
phpMyAdmin is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
ClamAV is prone to multiple vulnerabilities:
- An integer-overflow vulnerability.
- A format-string vulnerability.
- A denial-of-service vulnerability.
The first two issues may permit attackers to execute arbitrary code, which can facilitate a compromise of an affected computer.
If an attacker can successfully exploit the denial-of-service issue, this may
crash the affected application, which may aid an attacker in further attacks if the antivirus software no longer works.
No exploitations of these vulnerabilities are yet known and may not
appear. But those most concerned with security might want to move to an alternative anti-virus program (avoiding Symantec's Norton Anti-Virus
which itself has had several problems).
Sysop: | Gate Keeper |
---|---|
Location: | Shelby, NC |
Users: | 790 |
Nodes: | 20 (0 / 20) |
Uptime: | 40:00:12 |
Calls: | 12,115 |
Calls today: | 5 |
Files: | 5,294 |
D/L today: |
72 files (9,959K bytes) |
Messages: | 564,927 |