Intrusion Prevention

Clam.AntiVirus.PE.Rebuilding.Heap.Buffer.Overflow

Description

This indicates an attack attempt to exploit an Integer Overflow vulnerability in ClamAV.
The vulnerability is caused by the vulnerable application's failure to perform proper boundary checks on user supplied data. Successful attacks may allow a remote attacker to execute arbitrary code.

Affected Products

ClamAV 0.88.4

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Apply the most recent upgrades or patches from the vendor:
http://www.clamav.net/lang/en/

CVE References

CVE-2006-4182