CVE-2003-0946 — Use of Externally-Controlled Format String in Anti-virus Clamav
6 documents6 sources
Severity
7.5HIGHNVD
EPSS
2.0%
top 16.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 15
Latest updateApr 29
Description
Format string vulnerability in clamav-milter for Clam AntiVirus 0.60 through 0.60p, and other versions before 0.65, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in the email address argument of a "MAIL FROM" command.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4
Affected Packages2 packages
🔴Vulnerability Details
3💥Exploits & PoCs
1Exploit-DB
▶
📋Vendor Advisories
1Debian▶
CVE-2003-0946: clamav - Format string vulnerability in clamav-milter for Clam AntiVirus 0.60 through 0.6...↗2003