Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: ClamAV: win32

libclamav crashes in cli_ctime

 

 

ClamAV win32 RSS feed   Index | Next | Previous | View Threaded


ageraldnaveen at yahoo

Mar 4, 2008, 4:36 AM

Post #1 of 2 (926 views)
Permalink
libclamav crashes in cli_ctime

I'm using the stable 0.92.1 kit on Windows.

cli_ctime tries to convert the given time into readable string. There is no
check in this function for invalid timestamp (time_t). As a result, a PE binary
with a wrong/invalid timestamp crashes in cli_ctime, as ctime returns NULL and
there is no code to handle it.

If ctime returns null, it should be handled ; maybe "invalid time" can be
copied to the buffer.

Any idea if there is any fix coming up on this?

Thanks




____________________________________________________________________________________
Never miss a thing. Make Yahoo your home page.
http://www.yahoo.com/r/hs
_______________________________________________
http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-win32


njh at bandsman

Mar 4, 2008, 5:17 AM

Post #2 of 2 (848 views)
Permalink
Re: libclamav crashes in cli_ctime [In reply to]

Gerald Naveen wrote:
> I'm using the stable 0.92.1 kit on Windows.
>
> cli_ctime tries to convert the given time into readable string. There is no
> check in this function for invalid timestamp (time_t). As a result, a PE binary
> with a wrong/invalid timestamp crashes in cli_ctime, as ctime returns NULL and
> there is no code to handle it.
>
> If ctime returns null, it should be handled ; maybe "invalid time" can be
> copied to the buffer.
>
> Any idea if there is any fix coming up on this?

Please raise a bug on bugzilla.
>
> Thanks


--
Nigel Horne. Adjudicator, Arranger, Band Trainer, Conductor, Composer, Tutor.
NJH Music, Barnsley, UK. ICQ#20252325
njh [at] bandsman http://www.bandsman.co.uk

ClamAV win32 RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.