CVE-2007-4510Anti-virus Clamav vulnerability

5 documents5 sources
Severity
4.3MEDIUMNVD
EPSS
3.2%
top 12.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 23
Latest updateMay 1

Description

ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other products, allows remote attackers to cause a denial of service (application crash) via (1) a crafted RTF file, which triggers a NULL dereference in the cli_scanrtf function in libclamav/rtf.c; or (2) a crafted HTML document with a data: URI, which triggers a NULL dereference in the cli_html_normalise function in libclamav/htmlnorm.c. NOTE: some of these details are obtained from third party information.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

NVDkolab/kolab_server7 versions+6
Debianclamav/clamav< 0.91.2-1~volatile1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-rjmp-h7fr-8g38: ClamAV before 02022-05-01
OSV
CVE-2007-4510: ClamAV before 02007-08-23
CVEList
CVE-2007-4510: ClamAV before 02007-08-23

📋Vendor Advisories

1
Debian
CVE-2007-4510: clamav - ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other pro...2007
CVE-2007-4510 — Clam Anti-virus Clamav vulnerability | cvebase