Lucene search

K
cve[email protected]CVE-2005-1923
HistoryJul 05, 2005 - 4:00 a.m.

CVE-2005-1923

2005-07-0504:00:00
web.nvd.nist.gov
32
cve-2005-1923
clam antivirus
clamav
mszipd.c
denial of service
cpu consumption
infinite loop
remote attackers
nvd

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

8.9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

53.6%

The ENSURE_BITS macro in mszipd.c for Clam AntiVirus (ClamAV) 0.83, and other versions vefore 0.86, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a cabinet (CAB) file with the cffile_FolderOffset field set to 0xff, which causes a zero-length read.

Affected configurations

NVD
Node
clam_anti-virusclamavMatch0.83
OR
clam_anti-virusclamavMatch0.84_rc1
OR
clam_anti-virusclamavMatch0.84_rc2
OR
clam_anti-virusclamavMatch0.85
OR
clam_anti-virusclamavMatch0.85.1

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

8.9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

53.6%