10
CVSSv2

CVE-2008-0318

Published: 12/02/2008 Updated: 07/03/2011
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer overflow in the cli_scanpe function in libclamav in ClamAV prior to 0.92.1, as used in clamd, allows remote malicious users to cause a denial of service and possibly execute arbitrary code via a crafted Petite packed PE file, which triggers a heap-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

clam anti-virus clamav

Vendor Advisories

Debian Bug report logs - #458532 Clamav vulnerable to symlink attack Package: clamav; Maintainer for clamav is ClamAV Team <pkg-clamav-devel@listsaliothdebianorg>; Source for clamav is src:clamav (PTS, buildd, popcon) Reported by: Neil McGovern <neilm@debianorg> Date: Tue, 1 Jan 2008 14:03:02 UTC Severity: impo ...