Description
Heap-based buffer overflow in spin.c in libclamav in ClamAV 0.92.1 allows remote attackers to execute arbitrary code via a crafted PeSpin packed PE binary with a modified length value.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4 Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-q36h-8f75-xxcm: Heap-based buffer overflow in spin↗2022-05-01 ▶ CVEListCVE-2008-0314: Heap-based buffer overflow in spin↗2008-04-16 ▶ OSVCVE-2008-0314: Heap-based buffer overflow in spin↗2008-04-16 ▶ 📋Vendor Advisories
5Red Hatkernel: qla2xxx NPIV vport management pseudofiles are world writable↗2010-01-19 ▶ Red Hatgedit: untrusted python modules search path↗2008-08-06 ▶ Red Hatclamav: PeSpin Heap Overflow Vulnerability↗2008-04-15 ▶ DebianCVE-2008-0314: clamav - Heap-based buffer overflow in spin.c in libclamav in ClamAV 0.92.1 allows remote...↗2008 ▶ Red Hatkernel: ipv6_hop_jumbo remote system crash↗2007-09-07 ▶ 💬Community
4BugzillaCVE-2007-4567 kernel: ipv6_hop_jumbo remote system crash↗2009-12-18 ▶ BugzillaCVE-2008-0314 clamav: PeSpin Heap Overflow Vulnerability↗2008-04-16 ▶ BugzillaCVE-2007-5938 NULL dereference in iwl driver↗2007-11-15 ▶ BugzillaCVE-2007-5906 kernel-xen 3.1.1 virtual guest system denial of service (hypervisor crash) possibility↗2007-11-12 ▶