Interesting... Decompression Bombs

Matt Kettler mkettler at EVI-INC.COM
Thu Feb 12 17:09:49 GMT 2004


At 09:45 AM 2/12/2004, Martin Hepworth wrote:
>Bob Jones wrote:
> > An interesting issue for those of us that run virus scanners for mail.
> > Check out: http://cheerleader.yoz.com/archives/001711.html
> >
> > --
> > Bob Jones
> > OIIT
> > The Board of Regents
> > The University System of Georgia
>
>Possibbly something to do with the rush 0.66 release of ClamAV and the
>DOS attack is mentions????

No, the DOS attack involves decoding of invalid uuencoded streams.

There's an explanation on bugtraq for those that are concerned. Look for
the subject
"<http://www.securityfocus.com/archive/1/353186/2004-02-07/2004-02-13/1>clamav
0.65 remote DOS exploit " in the bugtraq archives of your choice. (google
searches work well too).



More information about the MailScanner mailing list