4.3
CVSSv2

CVE-2007-4510

Published: 23/08/2007 Updated: 29/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

ClamAV prior to 0.91.2, as used in Kolab Server 2.0 up to and including 2.2beta1 and other products, allows remote malicious users to cause a denial of service (application crash) via (1) a crafted RTF file, which triggers a NULL dereference in the cli_scanrtf function in libclamav/rtf.c; or (2) a crafted HTML document with a data: URI, which triggers a NULL dereference in the cli_html_normalise function in libclamav/htmlnorm.c. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

kolab kolab server 2.0

clam anti-virus clamav

kolab kolab server 2.1

kolab kolab server 2.2beta1

kolab kolab server 2.0.1

kolab kolab server 2.0.2

kolab kolab server 2.0.3

kolab kolab server 2.0.4

Vendor Advisories

Several remote vulnerabilities have been discovered in the Clam anti-virus toolkit The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-4510 It was discovered that the RTF and RFC2397 parsers can be tricked into dereferencing a NULL pointer, resulting in denial of service CVE-2007-4560 It was d ...