Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-1311
HistoryApr 09, 2010 - 12:00 a.m.

CVE-2010-1311

2010-04-0900:00:00
ubuntu.com
ubuntu.com
11

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.216 Low

EPSS

Percentile

96.5%

The qtm_decompress function in libclamav/mspack.c in ClamAV before 0.96
allows remote attackers to cause a denial of service (memory corruption and
application crash) via a crafted CAB archive that uses the Quantum (aka .Q)
compression format. NOTE: some of these details are obtained from third
party information.

Bugs

Notes

Author Note
jdstrand DoS via crafted CAB file
OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchclamav< 0.95.3+dfsg-1ubuntu0.09.04~dapper3UNKNOWN
ubuntu8.04noarchclamav< 0.95.3+dfsg-1ubuntu0.09.04~hardy2.3UNKNOWN
ubuntu8.10noarchclamav< 0.95.3+dfsg-1ubuntu0.09.04~intrepid3UNKNOWN
ubuntu9.04noarchclamav< 0.95.3+dfsg-1ubuntu0.09.04.1UNKNOWN
ubuntu9.10noarchclamav< 0.95.3+dfsg-1ubuntu0.09.10.1UNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.216 Low

EPSS

Percentile

96.5%