CVE-2003-0946Use of Externally-Controlled Format String in Anti-virus Clamav

6 documents6 sources
Severity
7.5HIGHNVD
EPSS
2.0%
top 16.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 15
Latest updateApr 29

Description

Format string vulnerability in clamav-milter for Clam AntiVirus 0.60 through 0.60p, and other versions before 0.65, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in the email address argument of a "MAIL FROM" command.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

Debianclamav/clamav< 0.65+3
NVDclam_anti-virus/clamav0.60, 0.60p+1

🔴Vulnerability Details

3
GHSA
GHSA-r485-qff8-c9cc: Format string vulnerability in clamav-milter for Clam AntiVirus 02022-04-29
OSV
CVE-2003-0946: Format string vulnerability in clamav-milter for Clam AntiVirus 02003-12-15
CVEList
CVE-2003-0946: Format string vulnerability in clamav-milter for Clam AntiVirus 02003-11-18

💥Exploits & PoCs

1
Exploit-DB
EMC AlphaStor Library Manager < 4.0 build 910 - Opcode 0x4f Buffer Overflow (Metasploit)2017-09-14

📋Vendor Advisories

1
Debian
CVE-2003-0946: clamav - Format string vulnerability in clamav-milter for Clam AntiVirus 0.60 through 0.6...2003
CVE-2003-0946 — Clam Anti-virus Clamav vulnerability | cvebase