ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted xz archive file.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://ubuntu.com/usn/usn-2594-1 | vendor advisory |
https://security.gentoo.org/glsa/201512-08 | vendor advisory |
http://www.securityfocus.com/bid/74472 | vdb entry |
http://blog.clamav.net/2015/04/clamav-0987-has-been-released.html | patch vendor advisory |
http://lists.opensuse.org/opensuse-updates/2015-05/msg00024.html | vendor advisory |