CVE-2008-0318Improper Restriction of Operations within the Bounds of a Memory Buffer in Anti-virus Clamav

CWE-1898 documents7 sources
Severity
10.0CRITICALNVD
EPSS
15.6%
top 5.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12
Latest updateMay 1

Description

Integer overflow in the cli_scanpe function in libclamav in ClamAV before 0.92.1, as used in clamd, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Petite packed PE file, which triggers a heap-based buffer overflow.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

Debianclamav/clamav< 0.92.1~dfsg-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4q4c-x269-7rpf: Integer overflow in the cli_scanpe function in libclamav in ClamAV before 02022-05-01
OSV
CVE-2008-0318: Integer overflow in the cli_scanpe function in libclamav in ClamAV before 02008-02-12
CVEList
CVE-2008-0318: Integer overflow in the cli_scanpe function in libclamav in ClamAV before 02008-02-12

📋Vendor Advisories

3
Red Hat
Gnumeric: untrusted python modules search path2008-08-06
Debian
CVE-2008-0318: clamav - Integer overflow in the cli_scanpe function in libclamav in ClamAV before 0.92.1...2008
Red Hat
clamav: Integer overflow in libclamav

💬Community

1
Bugzilla
CVE-2008-0318 clamav: Integer overflow in libclamav2008-02-14
CVE-2008-0318 — Clam Anti-virus Clamav vulnerability | cvebase