Several remote vulnerabilities have been discovered in the Clam anti-virus toolkit. The Common Vulnerabilities and Exposures project identifies the following problems:
Damian Put discovered that a buffer overflow in the handler for PeSpin binaries may lead to the execution of arbitrary code.
Alin Rad Pop discovered that a buffer overflow in the handler for Upack PE binaries may lead to the execution of arbitrary code.
Damian Put and Thomas Pollet discovered that a buffer overflow in the handler for WWPack-compressed PE binaries may lead to the execution of arbitrary code.
For the stable distribution (etch) these problems have been fixed in version 0.90.1dfsg-3etch11.
For the unstable distribution (sid) these problems have been fixed in version 0.92.1~dfsg2-1.
We recommend that you upgrade your clamav packages.
MD5 checksums of the listed files are available in the original advisory.