4.3
CVSSv2

CVE-2008-3688

Published: 14/08/2008 Updated: 08/02/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

sockethandler.cpp in HTTP Antivirus Proxy (HAVP) 0.88 allows remote malicious users to cause a denial of service (hang) by connecting to a non-responsive server, which triggers an infinite loop due to an uninitialized variable.

Vulnerable Product Search on Vulmon Subscribe to Product

havp http antivirus proxy 0.88

Vendor Advisories

Debian Bug report logs - #496034 CVE-2008-3688: DoS by infinite loop Package: havp; Maintainer for havp is ClamAV Team <pkg-clamav-devel@listsaliothdebianorg>; Source for havp is src:havp (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Fri, 22 Aug 2008 08:27:02 UTC Severity: ...