USN-1076-1: ClamAV vulnerability
28 February 2011
Releases
Packages
- clamav -
Details
It was discovered that the Microsoft Office processing code in libclamav
improperly handled certain Visual Basic for Applications (VBA) data. This
could allow a remote attacker to craft a document that could crash clamav
or possibly execute arbitrary code.
In the default installation, attackers would be isolated by the
ClamAV AppArmor profile.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 9.10
Ubuntu 10.10
Ubuntu 10.04
In general, a standard system update will make all the necessary changes.