6.4
CVSSv2

CVE-2007-0898

Published: 16/02/2007 Updated: 29/07/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV prior to 0.90 allows remote malicious users to overwrite arbitrary files via a .. (dot dot) in the id MIME header parameter in a multi-part message.

Vulnerable Product Search on Vulmon Subscribe to Product

clam anti-virus clamav 0.21

clam anti-virus clamav 0.22

clam anti-virus clamav 0.23

clam anti-virus clamav 0.60p

clam anti-virus clamav 0.65

clam anti-virus clamav 0.73

clam anti-virus clamav 0.74

clam anti-virus clamav 0.52

clam anti-virus clamav 0.53

clam anti-virus clamav 0.68.1

clam anti-virus clamav 0.70

clam anti-virus clamav 0.80

clam anti-virus clamav 0.80_rc1

clam anti-virus clamav 0.84

clam anti-virus clamav 0.84_rc1

clam anti-virus clamav 0.86_rc1

clam anti-virus clamav 0.87

clam anti-virus clamav 0.15

clam anti-virus clamav 0.20

clam anti-virus clamav 0.54

clam anti-virus clamav 0.60

clam anti-virus clamav 0.71

clam anti-virus clamav 0.72

clam anti-virus clamav 0.80_rc2

clam anti-virus clamav 0.80_rc3

clam anti-virus clamav 0.24

clam anti-virus clamav 0.51

clam anti-virus clamav 0.67

clam anti-virus clamav 0.68

clam anti-virus clamav 0.75

clam anti-virus clamav 0.75.1

clam anti-virus clamav 0.82

clam anti-virus clamav 0.83

clam anti-virus clamav 0.86.1

clam anti-virus clamav 0.86.2

clam anti-virus clamav 0.80_rc4

clam anti-virus clamav 0.84_rc2

clam anti-virus clamav 0.85

clam anti-virus clamav 0.87.1

clam anti-virus clamav 0.88

clam anti-virus clamav 0.81

clam anti-virus clamav 0.81_rc1

clam anti-virus clamav 0.85.1

clam anti-virus clamav 0.86

clam anti-virus clamav 0.88.1

clam anti-virus clamav 0.88.3

clam anti-virus clamav 0.88.4

clam anti-virus clamav

Vendor Advisories

Debian Bug report logs - #411118 clamav: CVE-2007-0897 - CAB File Denial of Service Vulnerability Package: clamav; Maintainer for clamav is ClamAV Team <pkg-clamav-devel@listsaliothdebianorg>; Source for clamav is src:clamav (PTS, buildd, popcon) Reported by: intrigeri@boumorg Date: Fri, 16 Feb 2007 11:18:01 UTC Sever ...
Debian Bug report logs - #411117 clamav: CVE-2007-0898 - MIME Header Directory Traversal Package: clamav; Maintainer for clamav is ClamAV Team <pkg-clamav-devel@listsaliothdebianorg>; Source for clamav is src:clamav (PTS, buildd, popcon) Reported by: intrigeri@boumorg Date: Fri, 16 Feb 2007 11:15:02 UTC Severity: seri ...