CVE-2008-1833Improper Restriction of Operations within the Bounds of a Memory Buffer in Anti-virus Clamav

Severity
7.5HIGHNVD
EPSS
8.4%
top 7.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 16
Latest updateMay 1

Description

Heap-based buffer overflow in pe.c in libclamav in ClamAV 0.92.1 allows remote attackers to execute arbitrary code via a crafted WWPack compressed PE binary.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

Debianclamav/clamav< 0.92.1~dfsg2-1.1+3

🔴Vulnerability Details

3
GHSA
GHSA-qp3p-jxgq-6c7f: Heap-based buffer overflow in pe2022-05-01
OSV
CVE-2008-1833: Heap-based buffer overflow in pe2008-04-16
CVEList
CVE-2008-1833: Heap-based buffer overflow in pe2008-04-16

📋Vendor Advisories

2
Red Hat
clamav: PE WWPack Heap Overflow Vulnerability2008-04-15
Debian
CVE-2008-1833: clamav - Heap-based buffer overflow in pe.c in libclamav in ClamAV 0.92.1 allows remote a...2008

💬Community

1
Bugzilla
CVE-2008-1833 clamav: PE WWPack Heap Overflow Vulnerability2008-04-16
CVE-2008-1833 — Clam Anti-virus Clamav vulnerability | cvebase