Description: A vulnerability has been reported in ClamAV, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to a boundary error in "libclamav/upx.c" when unpacking executable files compressed with UPX. This can be exploited to cause a heap-based buffer overflow and potentially allows arbitrary code execution via a specially-crafted UPX packed file.
The vulnerability has been reported in versions 0.80 through 0.87.1.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.