6.8
CVSSv2

CVE-2011-1003

Published: 23/02/2011 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Double free vulnerability in the vba_read_project_strings function in vba_extract.c in libclamav in ClamAV prior to 0.97 might allow remote malicious users to execute arbitrary code via crafted Visual Basic for Applications (VBA) data in a Microsoft Office document. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

clamav clamav

clamav clamav 0.95.2

clamav clamav 0.86.2

clamav clamav 0.88.5

clamav clamav 0.02

clamav clamav 0.92

clamav clamav 0.95

clamav clamav 0.8

clamav clamav 0.15

clamav clamav 0.90

clamav clamav 0.75.1

clamav clamav 0.65

clamav clamav 0.88.7

clamav clamav 0.81

clamav clamav 0.86

clamav clamav 0.01

clamav clamav 0.92_p0

clamav clamav 0.85

clamav clamav 0.84

clamav clamav 0.3

clamav clamav 0.91.2_p0

clamav clamav 0.93.1

clamav clamav 0.95.1

clamav clamav 0.93

clamav clamav 0.70

clamav clamav 0.68.1

clamav clamav 0.96.4

clamav clamav 0.03

clamav clamav 0.87.1

clamav clamav 0.9

clamav clamav 0.74

clamav clamav 0.93.3

clamav clamav 0.88

clamav clamav 0.91

clamav clamav 0.86.1

clamav clamav 0.71

clamav clamav 0.88.1

clamav clamav 0.60p

clamav clamav 0.94

clamav clamav 0.80

clamav clamav 0.91.2

clamav clamav 0.96.3

clamav clamav 0.90.3

clamav clamav 0.85.1

clamav clamav 0.96.2

clamav clamav 0.13

clamav clamav 0.10

clamav clamav 0.94.2

clamav clamav 0.96.1

clamav clamav 0.90.1_p0

clamav clamav 0.12

clamav clamav 0.88.7_p0

clamav clamav 0.23

clamav clamav 0.90.3_p1

clamav clamav 0.60

clamav clamav 0.88.2

clamav clamav 0.83

clamav clamav 0.20

clamav clamav 0.88.4

clamav clamav 0.90.3_p0

clamav clamav 0.14

clamav clamav 0.24

clamav clamav 0.96

clamav clamav 0.90.2_p0

clamav clamav 0.66

clamav clamav 0.51

clamav clamav 0.52

clamav clamav 0.22

clamav clamav 0.72

clamav clamav 0.75

clamav clamav 0.05

clamav clamav 0.54

clamav clamav 0.87

clamav clamav 0.21

clamav clamav 0.88.7_p1

clamav clamav 0.67-1

clamav clamav 0.90.1

clamav clamav 0.91.1

clamav clamav 0.95.3

clamav clamav 0.88.3

clamav clamav 0.67

clamav clamav 0.92.1

clamav clamav 0.90.2

clamav clamav 0.68

clamav clamav 0.53

clamav clamav 0.93.2

clamav clamav 0.88.6

clamav clamav 0.94.1

clamav clamav 0.80_rc

clamav clamav 0.82

clamav clamav 0.73

Vendor Advisories

Debian Bug report logs - #617444 clamav: (PRSC) Please backport fix for CVE-2011-1003 Package: clamav; Maintainer for clamav is ClamAV Team <pkg-clamav-devel@listsaliothdebianorg>; Source for clamav is src:clamav (PTS, buildd, popcon) Reported by: Jonathan Wiltshire <jmw@debianorg> Date: Tue, 8 Mar 2011 23:51:02 ...
It was discovered that the Microsoft Office processing code in libclamav improperly handled certain Visual Basic for Applications (VBA) data This could allow a remote attacker to craft a document that could crash clamav or possibly execute arbitrary code ...