7.8
CVSSv2

CVE-2009-1270

Published: 08/04/2009 Updated: 10/02/2022
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

libclamav/untar.c in ClamAV prior to 0.95 allows remote malicious users to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

clamav clamav

debian debian linux 4.0

debian debian linux 5.0

canonical ubuntu linux 8.10

Vendor Advisories

Debian Bug report logs - #523016 clamav vulnerability Package: clamav; Maintainer for clamav is ClamAV Team <pkg-clamav-devel@listsaliothdebianorg>; Source for clamav is src:clamav (PTS, buildd, popcon) Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> Date: Tue, 7 Apr 2009 21:57:02 UTC Severity: g ...
It was discovered that ClamAV did not properly verify its input when processing TAR archives A remote attacker could send a specially crafted TAR file and cause a denial of service via infinite loop (CVE-2009-1270) ...
Several vulnerabilities have been discovered in the ClamAV anti-virus toolkit: CVE-2008-6680 Attackers can cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error CVE-2009-1270 Attackers can cause a denial of service (infinite loop) via a crafted tar file that causes (1) clamd and (2) clamscan ...