Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 04:45:47 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=1487424921&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2F1005-advisories%2FMDVSA-2010-110.txt%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.1487424921.1338180347.1338180347.1338180347.1%3B%2B__utmz%3D32867617.1338180347.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) Mandriva Linux Security Advisory 2010-110 http://packetstormsecurity.org/files/90029/MDVSA-2010-110.txt http://packetstormsecurity.org/files/90029/MDVSA-2010-110.txt http://packetstormsecurity.org/files/90029/Mandriva-Linux-Security-Advisory-2010-110.html Fri, 28 May 2010 00:59:49 GMT Mandriva Linux Security Advisory 2010-110 - The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length and the real stream length. Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV 0.96 allows remote attackers to cause a denial of service (crash) via a crafted PE icon that triggers an out-of-bounds read, related to improper rounding during scaling. This update provides clamav 0.96.1 which is not vulnerable to these issues.