4.3
CVSSv2

CVE-2007-3725

Published: 12/07/2007 Updated: 15/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The RAR VM (unrarvm.c) in Clam Antivirus (ClamAV) prior to 0.91 allows user-assisted remote malicious users to cause a denial of service (crash) via a crafted RAR archive, resulting in a NULL pointer dereference.

Vulnerable Product Search on Vulmon Subscribe to Product

clam anti-virus clamav 0.51

clam anti-virus clamav 0.52

clam anti-virus clamav 0.21

clam anti-virus clamav 0.22

clam anti-virus clamav 0.60p

clam anti-virus clamav 0.65

clam anti-virus clamav 0.73

clam anti-virus clamav 0.74

clam anti-virus clamav 0.80_rc4

clam anti-virus clamav 0.81

clam anti-virus clamav 0.85.1

clam anti-virus clamav 0.86

clam anti-virus clamav 0.88.1

clam anti-virus clamav 0.88.3

clam anti-virus clamav 0.90_rc2

clam anti-virus clamav 0.90_rc3

clam anti-virus clamav 0.15

clam anti-virus clamav 0.20

clam anti-virus clamav 0.23

clam anti-virus clamav 0.24

clam anti-virus clamav 0.67

clam anti-virus clamav 0.68

clam anti-virus clamav 0.75

clam anti-virus clamav 0.75.1

clam anti-virus clamav 0.81_rc1

clam anti-virus clamav 0.82

clam anti-virus clamav 0.86.1

clam anti-virus clamav 0.86.2

clam anti-virus clamav 0.88.4

clam anti-virus clamav 0.88.5

clam anti-virus clamav 0.68.1

clam anti-virus clamav 0.70

clam anti-virus clamav 0.80

clam anti-virus clamav 0.80_rc1

clam anti-virus clamav 0.83

clam anti-virus clamav 0.84

clam anti-virus clamav 0.84_rc1

clam anti-virus clamav 0.86_rc1

clam anti-virus clamav 0.87

clam anti-virus clamav 0.88.6

clam anti-virus clamav 0.88.7

clam anti-virus clamav 0.53

clam anti-virus clamav 0.54

clam anti-virus clamav 0.60

clam anti-virus clamav 0.71

clam anti-virus clamav 0.72

clam anti-virus clamav 0.80_rc2

clam anti-virus clamav 0.80_rc3

clam anti-virus clamav 0.84_rc2

clam anti-virus clamav 0.85

clam anti-virus clamav 0.87.1

clam anti-virus clamav 0.88

clam anti-virus clamav 0.90

clam anti-virus clamav 0.90_rc1.1

Vendor Advisories

Debian Bug report logs - #437703 CVE-2007-3726: crafted RAR archive may cause crash Package: unrar; Maintainer for unrar is Martin Meredith <mez@debianorg>; Source for unrar is src:unrar-nonfree (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Mon, 13 Aug 2007 19:09:01 UTC Severity: normal T ...
A NULL pointer dereference has been discovered in the RAR VM of Clam Antivirus (ClamAV) which allows user-assisted remote attackers to cause a denial of service via a specially crafted RAR archives We are currently unable to provide fixed packages for the MIPS architectures Those packages will be installed in the security archive when they become ...

Exploits

source: wwwsecurityfocuscom/bid/24866/info Multiple applications using RAR are prone to a NULL-pointer dereference vulnerability A successful attack will result in denial-of-service conditions Attackers may also be able to exploit this issue to execute arbitrary code, but this has not been confirmed This issue affects the following: ...