CVE-2007-0898Path Traversal in Anti-virus Clamav

CWE-22Path Traversal7 documents6 sources
Severity
6.4MEDIUMNVD
EPSS
2.0%
top 16.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 16
Latest updateMay 1

Description

Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV before 0.90 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the id MIME header parameter in a multi-part message.

CVSS vector

AV:N/AC:L/C:N/I:P/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages2 packages

Debianclamav/clamav< 0.90-1+3
NVDclam_anti-virus/clamav0.88.6+47

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9298-v2wf-r563: Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV before 02022-05-01
CVEList
CVE-2007-0898: Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV before 02007-02-16
OSV
CVE-2007-0898: Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV before 02007-02-16

📋Vendor Advisories

1
Debian
CVE-2007-0898: clamav - Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV before 0.90 ...2007

💬Community

2
Bugzilla
0.90 fixes CVE-2007-0897 (MIME Header Handling) and CVE-2007-0898 (CAB File Processing) Denials of Service2007-02-19
Bugzilla
0.90 fixes CVE-2007-0897 (MIME Header Handling) and CVE-2007-0898 (CAB File Processing) Denials of Service2007-02-19
CVE-2007-0898 — Path Traversal in Anti-virus Clamav | cvebase