5
CVSSv2

CVE-2008-2713

Published: 16/06/2008 Updated: 08/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

libclamav/petite.c in ClamAV prior to 0.93.1 allows remote malicious users to cause a denial of service via a crafted Petite file that triggers an out-of-bounds read.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

clam anti-virus clamav 0.15

clam anti-virus clamav 0.52

clam anti-virus clamav 0.53

clam anti-virus clamav 0.54

clam anti-virus clamav 0.70

clam anti-virus clamav 0.71

clam anti-virus clamav 0.22

clam anti-virus clamav 0.23

clam anti-virus clamav 0.65

clam anti-virus clamav 0.67

clam anti-virus clamav 0.74

clam anti-virus clamav 0.75

clam anti-virus clamav 0.81

clam anti-virus clamav 0.81_rc1

clam anti-virus clamav 0.86

clam anti-virus clamav 0.86.1

clam anti-virus clamav 0.88.3

clam anti-virus clamav 0.88.4

clam anti-virus clamav 0.90_rc1.1

clam anti-virus clamav 0.90_rc2

clam anti-virus clamav 0.24

clam anti-virus clamav 0.51

clam anti-virus clamav 0.68

clam anti-virus clamav 0.68.1

clam anti-virus clamav 0.75.1

clam anti-virus clamav 0.80

clam anti-virus clamav 0.82

clam anti-virus clamav 0.83

clam anti-virus clamav 0.84

clam anti-virus clamav 0.86.2

clam anti-virus clamav 0.86_rc1

clam anti-virus clamav 0.88.5

clam anti-virus clamav 0.88.6

clam anti-virus clamav 0.90_rc3

clam anti-virus clamav 0.90rc1

clam anti-virus clamav 0.80_rc1

clam anti-virus clamav 0.80_rc2

clam anti-virus clamav 0.84_rc1

clam anti-virus clamav 0.84_rc2

clam anti-virus clamav 0.87

clam anti-virus clamav 0.87.1

clam anti-virus clamav 0.88.7

clam anti-virus clamav 0.90

clam anti-virus clamav 0.20

clam anti-virus clamav 0.21

clam anti-virus clamav 0.60

clam anti-virus clamav 0.60p

clam anti-virus clamav 0.72

clam anti-virus clamav 0.73

clam anti-virus clamav 0.80_rc3

clam anti-virus clamav 0.80_rc4

clam anti-virus clamav 0.85

clam anti-virus clamav 0.85.1

clam anti-virus clamav 0.88

clam anti-virus clamav 0.88.1

clam anti-virus clamav 0.90.1

clam anti-virus clamav 0.90.2

Vendor Advisories

Debian Bug report logs - #490925 CVE-2008-2713: DoS Package: libclamav4; Maintainer for libclamav4 is (unknown); Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Tue, 15 Jul 2008 11:36:02 UTC Severity: grave Tags: patch, security Fixed in versions clamav/0931dfsg-11, clamav/0931dfsg-volatile11 Don ...

References

CWE-399http://www.openwall.com/lists/oss-security/2008/06/15/2http://svn.clamav.net/websvn/diff.php?repname=clamav-devel&path=/branches/0.93/libclamav/petite.c&rev=3886https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1000http://www.securityfocus.com/bid/29750http://www.mandriva.com/security/advisories?name=MDVSA-2008:122http://secunia.com/advisories/30967http://kolab.org/security/kolab-vendor-notice-21.txthttp://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.htmlhttp://www.securitytracker.com/id?1020305http://secunia.com/advisories/30829http://secunia.com/advisories/31437http://sourceforge.net/project/shownotes.php?release_id=605577&group_id=86638http://www.openwall.com/lists/oss-security/2008/06/17/8https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00617.htmlhttp://secunia.com/advisories/31206http://secunia.com/advisories/30785http://security.gentoo.org/glsa/glsa-200808-07.xmlhttp://secunia.com/advisories/31091http://secunia.com/advisories/30657https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00763.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-07/msg00006.htmlhttp://lists.apple.com/archives/security-announce//2008/Sep/msg00005.htmlhttp://secunia.com/advisories/31576http://up2date.astaro.com/2008/08/up2date_asg_v7300_ga_released.htmlhttp://secunia.com/advisories/31882http://www.us-cert.gov/cas/techalerts/TA08-260A.htmlhttp://www.vupen.com/english/advisories/2008/1855/referenceshttp://www.vupen.com/english/advisories/2008/2584http://secunia.com/advisories/31167http://www.debian.org/security/2008/dsa-1616https://exchange.xforce.ibmcloud.com/vulnerabilities/43133https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=490925https://nvd.nist.gov