CVE-2007-1745Anti-virus Clamav vulnerability

8 documents7 sources
Severity
7.1HIGHNVD
CNA7.5OSV7.5
EPSS
2.2%
top 15.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 16
Latest updateMay 1

Description

The chm_decompress_stream function in libclamav/chmunpack.c in Clam AntiVirus (ClamAV) before 0.90.2 leaks file descriptors, which has unknown impact and attack vectors involving a crafted CHM file, a different vulnerability than CVE-2007-0897. NOTE: some of these details are obtained from third party information.

CVSS vector

AV:N/AC:M/C:N/I:N/A:CExploitability: 8.6 | Impact: 6.9

Affected Packages3 packages

Debianclamav/clamav< 0.90.2-1+3

🔴Vulnerability Details

3
GHSA
GHSA-q5hh-756j-4676: The chm_decompress_stream function in libclamav/chmunpack2022-05-01
OSV
CVE-2007-1745: The chm_decompress_stream function in libclamav/chmunpack2007-04-16
CVEList
CVE-2007-1745: The chm_decompress_stream function in libclamav/chmunpack2007-04-16

💥Exploits & PoCs

1
Exploit-DB
XOOPS Module wiwimod 0.4 - Remote File Inclusion2007-06-20

📋Vendor Advisories

1
Debian
CVE-2007-1745: clamav - The chm_decompress_stream function in libclamav/chmunpack.c in Clam AntiVirus (C...2007

💬Community

2
Bugzilla
CVE-2007-1745: clamav < 0.90.2 chm unpack issue2007-04-18
Bugzilla
possible vulnerabilities CVE-2007-17452007-04-17
CVE-2007-1745 — Clam Anti-virus Clamav vulnerability | cvebase