CVE-2008-1387Anti-virus Clamav vulnerability

7 documents7 sources
Severity
4.3MEDIUMNVD
EPSS
5.7%
top 9.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 16
Latest updateMay 1

Description

ClamAV before 0.93 allows remote attackers to cause a denial of service (CPU consumption) via a crafted ARJ archive, as demonstrated by the PROTOS GENOME test suite for Archive Formats.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Debianclamav/clamav< 0.92.1~dfsg2-1+3
NVDclam_anti-virus/clamav8 versions+7

Patches

🔴Vulnerability Details

3
GHSA
GHSA-g83c-vr3x-94r4: ClamAV before 02022-05-01
CVEList
CVE-2008-1387: ClamAV before 02008-04-16
OSV
CVE-2008-1387: ClamAV before 02008-04-16

📋Vendor Advisories

2
Red Hat
clamav: Endless loop / hang with crafted arj2008-05-15
Debian
CVE-2008-1387: clamav - ClamAV before 0.93 allows remote attackers to cause a denial of service (CPU con...2008

💬Community

1
Bugzilla
CVE-2008-1387 clamav: Endless loop / hang with crafted arj2008-04-15
CVE-2008-1387 — Clam Anti-virus Clamav vulnerability | cvebase