Damian Put discovered a heap overflow vulnerability in the UPX unpacker of the ClamAV anti-virus toolkit which could allow remote attackers to execute arbitrary code or cause denial of service.
For the stable distribution (sarge) this problem has been fixed in version 0.84-2.sarge.10.
For the stable distribution (sarge) this problem has been fixed in version 0.88.4-0volatile1 in the volatile archive.
For the unstable distribution (sid) this problem has been fixed in version 0.88.4-2.
We recommend that you upgrade your clamav packages.
MD5 checksums of the listed files are available in the original advisory.