CVE-2004-1876 — Anti-virus Clamav vulnerability
5 documents5 sources
Severity
4.6MEDIUMNVD
EPSS
0.1%
top 68.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 30
Latest updateApr 29
Description
The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name.
CVSS vector
AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4
Affected Packages2 packages
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-6xg8-8xmf-qghw: The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0↗2022-04-29
CVEList▶
CVE-2004-1876: The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0↗2005-05-10
OSV▶
CVE-2004-1876: The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0↗2004-03-30
📋Vendor Advisories
1Debian▶
CVE-2004-1876: clamav - The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) be...↗2004