4.3
CVSSv2

CVE-2007-0897

Published: 16/02/2007 Updated: 09/02/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Clam AntiVirus ClamAV prior to 0.90 does not close open file descriptors under certain conditions, which allows remote malicious users to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.

Vulnerable Product Search on Vulmon Subscribe to Product

clamav clamav

apple mac os x server

debian debian linux 3.1

Vendor Advisories

Debian Bug report logs - #411118 clamav: CVE-2007-0897 - CAB File Denial of Service Vulnerability Package: clamav; Maintainer for clamav is ClamAV Team <pkg-clamav-devel@listsaliothdebianorg>; Source for clamav is src:clamav (PTS, buildd, popcon) Reported by: intrigeri@boumorg Date: Fri, 16 Feb 2007 11:18:01 UTC Sever ...
Debian Bug report logs - #411117 clamav: CVE-2007-0898 - MIME Header Directory Traversal Package: clamav; Maintainer for clamav is ClamAV Team <pkg-clamav-devel@listsaliothdebianorg>; Source for clamav is src:clamav (PTS, buildd, popcon) Reported by: intrigeri@boumorg Date: Fri, 16 Feb 2007 11:15:02 UTC Severity: seri ...