Lucene search

K
freebsdFreeBSD6D18FE19-EE67-11D9-8310-0001020EED82
HistoryJun 29, 2005 - 12:00 a.m.

clamav -- MS-Expand file handling DoS vulnerability

2005-06-2900:00:00
vuxml.freebsd.org
10

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.006 Low

EPSS

Percentile

78.0%

An iDEFENSE Security Advisory reports:

Remote exploitation of an input validation error in Clam
AntiVirus ClamAV allows attackers to cause a denial of
service condition.
The vulnerability specifically exists due to improper
behavior during exceptional conditions.
Successful exploitation allows attackers to exhaust file
descriptors pool and memory. Anti-virus detection
functionality will fail if there is no file descriptors
available with which to open files. Remote exploitation
can be achieved by sending a malicious file in an e-mail
message or during an HTTP session.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchclamav< 0.86UNKNOWN
FreeBSDanynoarchclamav-devel< 20050620UNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.006 Low

EPSS

Percentile

78.0%

Related for 6D18FE19-EE67-11D9-8310-0001020EED82