Clam AntiVirus is "a multi-platform GPL anti-virus toolkit. The main purpose of which is integration into electronic mail servers". Microsoft Compressed HTML Help (CHM) files are commonly used for windows based software documentation. Remote exploitation of a input validation vulnerability in Clam AntiVirus's ClamAV could allow attackers to crash the virus scanning service.
Vulnerable Systems:
* Clam AntiVirus ClamAV version 0.88.4
Immune Systems:
* Clam AntiVirus ClamAV version 0.88.5
The vulnerability specifically exists due to improper handling of an specially crafted CHM file. While processing such a file, ClamAV may attempt to read an invalid memory location resulting in abnormal termination of the scanning service.