CVE-2007-0897
published 2007-02-16CVE-2007-0897: Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service…
PriorityP426high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.39%
87.5th percentile
Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x_server | < 10.4.11 | 10.4.11 |
| clam_anti-virus | clamav | <= 0.90.1 | — |
| clamav | clamav | < 0.90 | 0.90 |
| clamav | clamav | >= 0 < 0.90-1 | 0.90-1 |
| clamav | clamav | >= 0 < 0.90.2-1 | 0.90.2-1 |
| clamav | clamav | >= 0 < 0.90-1 | 0.90-1 |
| clamav | clamav | >= 0 < 0.90.2-1 | 0.90.2-1 |
| clamav | clamav | >= 0 < 0.90-1 | 0.90-1 |
| clamav | clamav | >= 0 < 0.90.2-1 | 0.90.2-1 |
| clamav | clamav | >= 0 < 0.90-1 | 0.90-1 |
| clamav | clamav | >= 0 < 0.90.2-1 | 0.90.2-1 |
| debian | clamav | < clamav 0.90.2-1 (bookworm) | clamav 0.90.2-1 (bookworm) |
| debian | clamav | < clamav 0.90-1 (bookworm) | clamav 0.90-1 (bookworm) |
| debian | debian_linux | — | — |
| ifenslave | ifenslave | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q5hh-756j-4676: The chm_decompress_stream function in libclamav/chmunpack
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2007-1745 [HIGH] GHSA-q5hh-756j-4676: The chm_decompress_stream function in libclamav/chmunpack
The chm_decompress_stream function in libclamav/chmunpack.c in Clam AntiVirus (ClamAV) before 0.90.2 leaks file descriptors, which has unknown impact and attack vectors involving a crafted CHM file, a different vulnerability than CVE-2007-0897. NOTE: some of these details are obtained from third party information.
GHSA
GHSA-3ppm-vmgq-rr54: Clam AntiVirus ClamAV before 0
ghsa_unreviewed·2022-05-01
CVE-2007-0897 [MEDIUM] CWE-772 GHSA-3ppm-vmgq-rr54: Clam AntiVirus ClamAV before 0
Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.
OSV
CVE-2007-1745: The chm_decompress_stream function in libclamav/chmunpack
osv·2007-04-16·CVSS 7.5
CVE-2007-1745 [HIGH] CVE-2007-1745: The chm_decompress_stream function in libclamav/chmunpack
The chm_decompress_stream function in libclamav/chmunpack.c in Clam AntiVirus (ClamAV) before 0.90.2 leaks file descriptors, which has unknown impact and attack vectors involving a crafted CHM file, a different vulnerability than CVE-2007-0897. NOTE: some of these details are obtained from third party information.
OSV
CVE-2007-0897: Clam AntiVirus ClamAV before 0
osv·2007-02-16·CVSS 7.5
CVE-2007-0897 [HIGH] CVE-2007-0897: Clam AntiVirus ClamAV before 0
Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.
Debian
CVE-2007-1745: clamav - The chm_decompress_stream function in libclamav/chmunpack.c in Clam AntiVirus (C...
vendor_debian·2007·CVSS 7.5
CVE-2007-1745 [HIGH] CVE-2007-1745: clamav - The chm_decompress_stream function in libclamav/chmunpack.c in Clam AntiVirus (C...
The chm_decompress_stream function in libclamav/chmunpack.c in Clam AntiVirus (ClamAV) before 0.90.2 leaks file descriptors, which has unknown impact and attack vectors involving a crafted CHM file, a different vulnerability than CVE-2007-0897. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 0.90.2-1)
bullseye: resolved (fixed in 0.90.2-1)
forky: resolved (fixed in 0.90.2-1)
sid: resolved (fixed in 0.90.2-1)
trixie: resolved (fixed in 0.90.2-1)
Debian
CVE-2007-0897: clamav - Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under cer...
vendor_debian·2007·CVSS 7.5
CVE-2007-0897 [HIGH] CVE-2007-0897: clamav - Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under cer...
Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.
Scope: local
bookworm: resolved (fixed in 0.90-1)
bullseye: resolved (fixed in 0.90-1)
forky: resolved (fixed in 0.90-1)
sid: resolved (fixed in 0.90-1)
trixie: resolved (fixed in 0.90-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-1745: clamav < 0.90.2 chm unpack issue
bugzilla·2007-04-18·CVSS 7.5
CVE-2007-1745 [HIGH] CVE-2007-1745: clamav < 0.90.2 chm unpack issue
CVE-2007-1745: clamav < 0.90.2 chm unpack issue
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1745
"The chm_decompress_stream function in libclamav/chmunpack.c in Clam AntiVirus
(ClamAV) before 0.90.2 leaks file descriptors, which has unknown impact and
attack vectors involving a crafted CHM file, a different vulnerability than
CVE-2007-0897. NOTE: some of these details are obtained from third party
information."
CVE-2007-1997 appears to be somewhat related and is said to affect 0.9x versions
before 0.90.2 only, however for this CVE I didn't find anything that would say
0.88.7 currently in FE5 and FE6 wouldn't be affected.
Discussion:
*** This bug has been marked as a duplicate of 236703 ***
Bugzilla
possible vulnerabilities CVE-2007-1745
bugzilla·2007-04-17·CVSS 7.5
CVE-2007-1745 [HIGH] possible vulnerabilities CVE-2007-1745
possible vulnerabilities CVE-2007-1745
See http://sourceforge.net/project/shownotes.php?release_id=500765
and http://www.heise-security.co.uk/news/88283
for more details.
The update to 0.90.2 will fix it.
Discussion:
Copy from bug #230075 comment #35:
----
0.88.7-2 should not be vulnerable to the issues fixed by 0.90.2.
CHM fd leak does not seem to triggerable by attackers (happens only when an
'fdopen()' fails, and there is a test whether open(2) returns !0 instead of <0).
0.90.x executes other code which might lead to the fd leak.
CAB scanning was disabled by the fix for CVE-2007-0897, and 0.88.7 does not
contain code for PDF scanning overall.
---
*** Bug 236948 has been marked as a duplicate of this bug. ***
Bugzilla
0.90 fixes CVE-2007-0897 (MIME Header Handling) and CVE-2007-0898 (CAB File Processing) Denials of Service
bugzilla·2007-02-19·CVSS 7.5
CVE-2007-0897 [HIGH] 0.90 fixes CVE-2007-0897 (MIME Header Handling) and CVE-2007-0898 (CAB File Processing) Denials of Service
0.90 fixes CVE-2007-0897 (MIME Header Handling) and CVE-2007-0898 (CAB File Processing) Denials of Service
+++ This bug was initially created as a clone of Bug #229202 +++
According to Secunia:
"Two vulnerabilities have been reported in ClamAV, which can be exploited by
malicious people to cause a DoS (Denial of Service).
1) Input passed via the "id" parameter when parsing MIME headers is not properly
sanitised before being used to create local files. This can be exploited to e.g.
overwrite the anti-virus signature file via directory traversal attacks,
preventing malware from being detected.
2) An file descriptor leak error in the processing of CAB files can be exploited
to e.g. prevent legitimate users from sending out valid archives via a specially
crafted CAB file with a cabinet hea
Bugzilla
0.90 fixes CVE-2007-0897 (MIME Header Handling) and CVE-2007-0898 (CAB File Processing) Denials of Service
bugzilla·2007-02-19·CVSS 7.5
CVE-2007-0897 [HIGH] 0.90 fixes CVE-2007-0897 (MIME Header Handling) and CVE-2007-0898 (CAB File Processing) Denials of Service
0.90 fixes CVE-2007-0897 (MIME Header Handling) and CVE-2007-0898 (CAB File Processing) Denials of Service
According to Secunia:
"Two vulnerabilities have been reported in ClamAV, which can be exploited by
malicious people to cause a DoS (Denial of Service).
1) Input passed via the "id" parameter when parsing MIME headers is not properly
sanitised before being used to create local files. This can be exploited to e.g.
overwrite the anti-virus signature file via directory traversal attacks,
preventing malware from being detected.
2) An file descriptor leak error in the processing of CAB files can be exploited
to e.g. prevent legitimate users from sending out valid archives via a specially
crafted CAB file with a cabinet header containing a record length of zero."
Please update the FC-6 p
CWE
Uncontrolled Resource Consumption
mitre_cwe
CWE-400 Uncontrolled Resource Consumption
CWE-400: Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
Modes of Introduction:
Phase: Operation
Note: The product could be operated in a system or environment with lower resource limits than expected, which might make it easier for attackers to consume all available resources.
Phase: System Configuration
Note: The product could be configured with lower resource limits than expected, which might make it easier for attackers to consume all available resources.
Phase: Architecture and Design
Note: The designer might not consider how to handle and throttle excessive resource requests, which typically requires careful planning to handle more gracefully than a crash or exit.
Phase: Implementation
Note: There are at
CWE
Missing Release of Resource after Effective Lifetime
mitre_cwe
CWE-772 Missing Release of Resource after Effective Lifetime
CWE-772: Missing Release of Resource after Effective Lifetime
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Availability. Impact: DoS: Resource Consumption (Other), DoS: Resource Consumption (Memory), DoS: Resource Consumption (CPU). An attacker that can influence the allocation of resources that are not properly released could deplete the available resource pool and prevent all other processes from accessing the same type of resource. Frequently-affected resources include memory, CPU, disk space, power or battery, etc.
Detection Methods:
Automated Static Analysis: Automated static analysis, commonly referred to as Static Application S
CWE
Missing Release of File Descriptor or Handle after Effective Lifetime
mitre_cwe
CWE-775 Missing Release of File Descriptor or Handle after Effective Lifetime
CWE-775: Missing Release of File Descriptor or Handle after Effective Lifetime
The product does not release a file descriptor or handle after its effective lifetime has ended, i.e., after the file descriptor/handle is no longer needed.
When a file descriptor or handle is not released after use (typically by explicitly closing it), attackers can cause a denial of service by consuming all available file descriptors/handles, or otherwise preventing other system processes from obtaining their own file descriptors/handles.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Availability. Impact: DoS: Resource Consumption (Other). An attacker that can influence the allocation of resources that are not properly released could deplete the available resource pool and preven
http://docs.info.apple.com/article.html?artnum=307562http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=475http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.suse.com/archive/suse-security-announce/2007-Feb/0004.htmlhttp://osvdb.org/32283http://secunia.com/advisories/24183http://secunia.com/advisories/24187http://secunia.com/advisories/24192http://secunia.com/advisories/24319http://secunia.com/advisories/24332http://secunia.com/advisories/24425http://secunia.com/advisories/29420http://security.gentoo.org/glsa/glsa-200703-03.xmlhttp://www.debian.org/security/2007/dsa-1263http://www.mandriva.com/security/advisories?name=MDKSA-2007:043http://www.securityfocus.com/bid/22580http://www.securitytracker.com/id?1017659http://www.vupen.com/english/advisories/2007/0623http://www.vupen.com/english/advisories/2008/0924/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/32531http://docs.info.apple.com/article.html?artnum=307562http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=475http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.suse.com/archive/suse-security-announce/2007-Feb/0004.htmlhttp://osvdb.org/32283http://secunia.com/advisories/24183http://secunia.com/advisories/24187http://secunia.com/advisories/24192http://secunia.com/advisories/24319http://secunia.com/advisories/24332http://secunia.com/advisories/24425http://secunia.com/advisories/29420http://security.gentoo.org/glsa/glsa-200703-03.xmlhttp://www.debian.org/security/2007/dsa-1263http://www.mandriva.com/security/advisories?name=MDKSA-2007:043http://www.securityfocus.com/bid/22580http://www.securitytracker.com/id?1017659http://www.vupen.com/english/advisories/2007/0623http://www.vupen.com/english/advisories/2008/0924/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/32531
2007-02-16
Published