Description: Two vulnerabilities have been reported in clamav, which can be exploited by malicious people to cause a DoS (Denial of Service).
1) An error in the "ENSURE_BITS()" macro when validating the header of a CAB file can lead to an infinite loop when the "cffile_cffile_FolderOffset" header value is set to "0xff".
Successful exploitation causes clamav to exhaust all system resources.
2) An error in the "cli_scanszdd()" function causes two file descriptors to be leaked whenever an attempt to decompress a file using the "cli_msexpand()" function fails. This causes clamav to exhaust all file descriptors after scanning approximately 1000 malformed files.
Solution: Update to version 0.86 or later.
Provided and/or discovered by: Discovered by anonymous person and reported via iDEFENSE.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.