CVE-2009-1372
Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL.
Date published : 2009-04-23
http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html