CVE-2007-4510
published 2007-08-23CVE-2007-4510: ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other products, allows remote attackers to cause a denial of service (application crash)…
PriorityP414medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.97%
77.9th percentile
ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other products, allows remote attackers to cause a denial of service (application crash) via (1) a crafted RTF file, which triggers a NULL dereference in the cli_scanrtf function in libclamav/rtf.c; or (2) a crafted HTML document with a data: URI, which triggers a NULL dereference in the cli_html_normalise function in libclamav/htmlnorm.c. NOTE: some of these details are obtained from third party information.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| clam_anti-virus | clamav | <= 0.91.2 | — |
| clamav | clamav | >= 0 < 0.91.2-1~volatile1 | 0.91.2-1~volatile1 |
| clamav | clamav | >= 0 < 0.91.2-1~volatile1 | 0.91.2-1~volatile1 |
| clamav | clamav | >= 0 < 0.91.2-1~volatile1 | 0.91.2-1~volatile1 |
| clamav | clamav | >= 0 < 0.91.2-1~volatile1 | 0.91.2-1~volatile1 |
| debian | clamav | < clamav 0.91.2-1~volatile1 (bookworm) | clamav 0.91.2-1~volatile1 (bookworm) |
| kolab | kolab_server | — | — |
| kolab | kolab_server | — | — |
| kolab | kolab_server | — | — |
| kolab | kolab_server | — | — |
| kolab | kolab_server | — | — |
| kolab | kolab_server | — | — |
| kolab | kolab_server | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rjmp-h7fr-8g38: ClamAV before 0
ghsa_unreviewed·2022-05-01
CVE-2007-4510 [MEDIUM] GHSA-rjmp-h7fr-8g38: ClamAV before 0
ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other products, allows remote attackers to cause a denial of service (application crash) via (1) a crafted RTF file, which triggers a NULL dereference in the cli_scanrtf function in libclamav/rtf.c; or (2) a crafted HTML document with a data: URI, which triggers a NULL dereference in the cli_html_normalise function in libclamav/htmlnorm.c. NOTE: some of these details are obtained from third party information.
OSV
CVE-2007-4510: ClamAV before 0
osv·2007-08-23·CVSS 4.3
CVE-2007-4510 [MEDIUM] CVE-2007-4510: ClamAV before 0
ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other products, allows remote attackers to cause a denial of service (application crash) via (1) a crafted RTF file, which triggers a NULL dereference in the cli_scanrtf function in libclamav/rtf.c; or (2) a crafted HTML document with a data: URI, which triggers a NULL dereference in the cli_html_normalise function in libclamav/htmlnorm.c. NOTE: some of these details are obtained from third party information.
Debian
CVE-2007-4510: clamav - ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other pro...
vendor_debian·2007·CVSS 4.3
CVE-2007-4510 [MEDIUM] CVE-2007-4510: clamav - ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other pro...
ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other products, allows remote attackers to cause a denial of service (application crash) via (1) a crafted RTF file, which triggers a NULL dereference in the cli_scanrtf function in libclamav/rtf.c; or (2) a crafted HTML document with a data: URI, which triggers a NULL dereference in the cli_html_normalise function in libclamav/htmlnorm.c. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 0.91.2-1~volatile1)
bullseye: resolved (fixed in 0.91.2-1~volatile1)
forky: resolved (fixed in 0.91.2-1~volatile1)
sid: resolved (fixed in 0.91.2-1~volatile1)
trixie: resolved (fixed in 0.91.2-1~volatile1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://docs.info.apple.com/article.html?artnum=307562http://kolab.org/security/kolab-vendor-notice-17.txthttp://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://secunia.com/advisories/26530http://secunia.com/advisories/26552http://secunia.com/advisories/26654http://secunia.com/advisories/26674http://secunia.com/advisories/26683http://secunia.com/advisories/26751http://secunia.com/advisories/26822http://secunia.com/advisories/26916http://secunia.com/advisories/29420http://security.gentoo.org/glsa/glsa-200709-14.xmlhttp://securityreason.com/securityalert/3054http://sourceforge.net/project/shownotes.php?release_id=533658http://www.debian.org/security/2007/dsa-1366http://www.mandriva.com/security/advisories?name=MDKSA-2007:172http://www.novell.com/linux/security/advisories/2007_18_sr.htmlhttp://www.securityfocus.com/bid/25398http://www.trustix.org/errata/2007/0026/http://www.vupen.com/english/advisories/2007/2952http://www.vupen.com/english/advisories/2008/0924/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/36173https://exchange.xforce.ibmcloud.com/vulnerabilities/36177https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00104.htmlhttps://wwws.clamav.net/bugzilla/show_bug.cgi?id=582https://wwws.clamav.net/bugzilla/show_bug.cgi?id=611http://docs.info.apple.com/article.html?artnum=307562http://kolab.org/security/kolab-vendor-notice-17.txthttp://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://secunia.com/advisories/26530http://secunia.com/advisories/26552http://secunia.com/advisories/26654http://secunia.com/advisories/26674http://secunia.com/advisories/26683http://secunia.com/advisories/26751http://secunia.com/advisories/26822http://secunia.com/advisories/26916http://secunia.com/advisories/29420http://security.gentoo.org/glsa/glsa-200709-14.xmlhttp://securityreason.com/securityalert/3054http://sourceforge.net/project/shownotes.php?release_id=533658http://www.debian.org/security/2007/dsa-1366http://www.mandriva.com/security/advisories?name=MDKSA-2007:172http://www.novell.com/linux/security/advisories/2007_18_sr.htmlhttp://www.securityfocus.com/bid/25398http://www.trustix.org/errata/2007/0026/http://www.vupen.com/english/advisories/2007/2952http://www.vupen.com/english/advisories/2008/0924/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/36173https://exchange.xforce.ibmcloud.com/vulnerabilities/36177https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00104.htmlhttps://wwws.clamav.net/bugzilla/show_bug.cgi?id=582https://wwws.clamav.net/bugzilla/show_bug.cgi?id=611
2007-08-23
Published