CVE-2009-1372
Publication date 23 April 2009
Last updated 24 July 2024
Ubuntu priority
Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL.
Notes
jdstrand
only 0.95 is affected (affected code not present-- part of url_hash_match() was moved out to the new cli_url_canon() in 0.95, and cli_url_canon() introduced the bug)