Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Heap-based buffer overflow in spin.c in libclamav in ClamAV 0.92.1 allows remote attackers to execute arbitrary code via a crafted PeSpin packed PE binary with a modified length value.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ClamAV libclamav库PeSpin堆溢出漏洞
Vulnerability Description
Clam AntiVirus是Unix的GPL杀毒工具包,很多邮件网关产品都在使用。 ClamAV中负责解压用PeSpin加密所包装的PE库的代码存在堆溢出漏洞,攻击者可能通过诱使用户处理畸形文件控制用户系统。 以下为libclamav/spin.c中的有漏洞代码段: 417key32 = cli_readint32(ep+0x2fee); ... 427cli_dbgmsg("spin: Resources (sect%d) appear to be compressed\n\tuncompressed
CVSS Information
N/A
Vulnerability Type
N/A