Lucene search

K
cve[email protected]CVE-2008-1835
HistoryApr 16, 2008 - 4:05 p.m.

CVE-2008-1835

2008-04-1616:05:00
CWE-20
web.nvd.nist.gov
28
4
clamav
bypass
scanning engine
rar file
cve-2008-1835
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.4 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.2%

ClamAV before 0.93 allows remote attackers to bypass the scanning enging via a RAR file with an invalid version number, which cannot be parsed by ClamAV but can be extracted by Winrar.

Affected configurations

NVD
Node
clam_anti-virusclamavRange0.92.1
OR
clam_anti-virusclamavMatch0.15
OR
clam_anti-virusclamavMatch0.20
OR
clam_anti-virusclamavMatch0.21
OR
clam_anti-virusclamavMatch0.22
OR
clam_anti-virusclamavMatch0.23
OR
clam_anti-virusclamavMatch0.24
OR
clam_anti-virusclamavMatch0.51
OR
clam_anti-virusclamavMatch0.52
OR
clam_anti-virusclamavMatch0.53
OR
clam_anti-virusclamavMatch0.54
OR
clam_anti-virusclamavMatch0.60
OR
clam_anti-virusclamavMatch0.60p
OR
clam_anti-virusclamavMatch0.65
OR
clam_anti-virusclamavMatch0.67
OR
clam_anti-virusclamavMatch0.68
OR
clam_anti-virusclamavMatch0.68.1
OR
clam_anti-virusclamavMatch0.70
OR
clam_anti-virusclamavMatch0.71
OR
clam_anti-virusclamavMatch0.72
OR
clam_anti-virusclamavMatch0.73
OR
clam_anti-virusclamavMatch0.74
OR
clam_anti-virusclamavMatch0.75
OR
clam_anti-virusclamavMatch0.75.1
OR
clam_anti-virusclamavMatch0.80
OR
clam_anti-virusclamavMatch0.80_rc1
OR
clam_anti-virusclamavMatch0.80_rc2
OR
clam_anti-virusclamavMatch0.80_rc3
OR
clam_anti-virusclamavMatch0.80_rc4
OR
clam_anti-virusclamavMatch0.81
OR
clam_anti-virusclamavMatch0.81_rc1
OR
clam_anti-virusclamavMatch0.82
OR
clam_anti-virusclamavMatch0.83
OR
clam_anti-virusclamavMatch0.84
OR
clam_anti-virusclamavMatch0.84_rc1
OR
clam_anti-virusclamavMatch0.84_rc2
OR
clam_anti-virusclamavMatch0.85
OR
clam_anti-virusclamavMatch0.85.1
OR
clam_anti-virusclamavMatch0.86
OR
clam_anti-virusclamavMatch0.86.1
OR
clam_anti-virusclamavMatch0.86.2
OR
clam_anti-virusclamavMatch0.86_rc1
OR
clam_anti-virusclamavMatch0.87
OR
clam_anti-virusclamavMatch0.87.1
OR
clam_anti-virusclamavMatch0.88
OR
clam_anti-virusclamavMatch0.88.1
OR
clam_anti-virusclamavMatch0.88.3
OR
clam_anti-virusclamavMatch0.88.4
OR
clam_anti-virusclamavMatch0.88.5
OR
clam_anti-virusclamavMatch0.88.6
OR
clam_anti-virusclamavMatch0.88.7
OR
clam_anti-virusclamavMatch0.90
OR
clam_anti-virusclamavMatch0.90.1
OR
clam_anti-virusclamavMatch0.90.2
OR
clam_anti-virusclamavMatch0.90_rc1.1
OR
clam_anti-virusclamavMatch0.90_rc2
OR
clam_anti-virusclamavMatch0.90_rc3
OR
clam_anti-virusclamavMatch0.90rc1
OR
clam_anti-virusclamavMatch0.91
OR
clam_anti-virusclamavMatch0.91.1
OR
clam_anti-virusclamavMatch0.91.2
OR
clam_anti-virusclamavMatch0.91rc1
OR
clam_anti-virusclamavMatch0.91rc2
OR
clam_anti-virusclamavMatch0.92

Social References

More

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.4 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.2%