CVE-2008-0728Clamav vulnerability

CWE-3996 documents6 sources
Severity
10.0CRITICALNVD
EPSS
1.8%
top 17.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 12
Latest updateMay 1

Description

The unmew11 function in libclamav/mew.c in libclamav in ClamAV before 0.92.1 has unknown impact and attack vectors that trigger "heap corruption."

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

debiandebian/clamav< clamav 0.92.1~dfsg-1 (bookworm)
Debianclamav/clamav< 0.92.1~dfsg-1+3
NVDclamav/clamav0.92+72

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jc8j-c4rx-788x: The unmew11 function in libclamav/mew2022-05-01
OSV
CVE-2008-0728: The unmew11 function in libclamav/mew2008-02-12

📋Vendor Advisories

2
Debian
CVE-2008-0728: clamav - The unmew11 function in libclamav/mew.c in libclamav in ClamAV before 0.92.1 has...2008
Red Hat
clamav: libclamav heap corruption

💬Community

1
Bugzilla
CVE-2008-0728 clamav: libclamav heap corruption2008-02-14