Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2007-6335Integer Overflow or Wraparound in Anti-virus Clamav

Severity
7.5HIGHNVD
EPSS
40.4%
top 2.64%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedDec 20
Latest updateMay 1

Description

Integer overflow in libclamav in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MEW packed PE file, which triggers a heap-based buffer overflow.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

Debianclamav/clamav< 0.92~dfsg-1~volatile2+3

🔴Vulnerability Details

3
GHSA
GHSA-7p49-jrwj-cxrj: Integer overflow in libclamav in ClamAV before 02022-05-01
CVEList
CVE-2007-6335: Integer overflow in libclamav in ClamAV before 02007-12-20
OSV
CVE-2007-6335: Integer overflow in libclamav in ClamAV before 02007-12-20

💥Exploits & PoCs

1
Exploit-DB
ClamAV 0.91.2 - libclamav MEW PE Buffer Overflow2008-01-07

📋Vendor Advisories

2
Red Hat
clamav: MEW PE File Integer Overflow Vulnerability (was CVE-2007-5759)2007-12-18
Debian
CVE-2007-6335: clamav - Integer overflow in libclamav in ClamAV before 0.92 allows remote attackers to e...2007

💬Community

1
Bugzilla
CVE-2007-6335 clamav: MEW PE File Integer Overflow Vulnerability (was CVE-2007-5759)2007-12-19
CVE-2007-6335 — Integer Overflow or Wraparound | cvebase