=====================================================================
                                 CERT-Renater

                      Note d'Information No. 2004/VULN161
_____________________________________________________________________

DATE                      : 08/04/2004

HARDWARE PLATFORM(S)      : /

OPERATING SYSTEM(S)       : Systems running ClamAV versions prior to 0.68.1.
                            
======================================================================

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200404-07
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                             http://security.gentoo.org
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: Normal
     Title: ClamAV RAR Archive Remote Denial Of Service Vulnerability

      Date: April 07, 2004
      Bugs: #45357
        ID: 200404-07

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

ClamAV is vulnerable to a denial of service attack when processing
certain RAR archives.

Background
==========

