Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-1003
HistoryFeb 23, 2011 - 12:00 a.m.

CVE-2011-1003

2011-02-2300:00:00
ubuntu.com
ubuntu.com
9

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.086 Low

EPSS

Percentile

94.5%

Double free vulnerability in the vba_read_project_strings function in
vba_extract.c in libclamav in ClamAV before 0.97 might allow remote
attackers to execute arbitrary code via crafted Visual Basic for
Applications (VBA) data in a Microsoft Office document. NOTE: some of these
details are obtained from third party information.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu8.04noarchclamav< 0.95.3+dfsg-1ubuntu0.09.04~hardy2.6UNKNOWN
ubuntu9.10noarchclamav< 0.95.3+dfsg-1ubuntu0.09.10.4UNKNOWN
ubuntu10.04noarchclamav< 0.96.5+dfsg-1ubuntu1.10.04.2UNKNOWN
ubuntu10.10noarchclamav< 0.96.5+dfsg-1ubuntu1.10.10.2UNKNOWN

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.086 Low

EPSS

Percentile

94.5%