CVE-2008-3913
published 2008-09-11CVE-2008-3913: Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified…
PriorityP419medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.06%
86.2th percentile
Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic".
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| clamav | clamav | < 0.94 | 0.94 |
| clamav | clamav | >= 0 < 0.94.dfsg-1 | 0.94.dfsg-1 |
| clamav | clamav | >= 0 < 0.94.dfsg-1 | 0.94.dfsg-1 |
| clamav | clamav | >= 0 < 0.94.dfsg-1 | 0.94.dfsg-1 |
| clamav | clamav | >= 0 < 0.94.dfsg-1 | 0.94.dfsg-1 |
| debian | clamav | < clamav 0.94.dfsg-1 (bookworm) | clamav 0.94.dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_msrc5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cr5r-q6mh-hr56: Multiple memory leaks in freshclam/manager
ghsa_unreviewed·2022-05-02
CVE-2008-3913 [MEDIUM] CWE-401 GHSA-cr5r-q6mh-hr56: Multiple memory leaks in freshclam/manager
Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic".
OSV
CVE-2008-3913: Multiple memory leaks in freshclam/manager
osv·2008-09-11·CVSS 5.0
CVE-2008-3913 [MEDIUM] CVE-2008-3913: Multiple memory leaks in freshclam/manager
Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic".
Microsoft
CVE-2008-3913: NIST NVD Details: https://nvd
vendor_msrc·2020-10-13·CVSS 5.0
CVE-2008-3913 [MEDIUM] CVE-2008-3913: NIST NVD Details: https://nvd
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2008-3913
Mariner: Mariner
[email protected]: [email protected]
Exploit Status: DOS:N/A
Remediation: clamav
Debian
CVE-2008-3913: clamav - Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow a...
vendor_debian·2008·CVSS 5.0
CVE-2008-3913 [MEDIUM] CVE-2008-3913: clamav - Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow a...
Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic".
Scope: local
bookworm: resolved (fixed in 0.94.dfsg-1)
bullseye: resolved (fixed in 0.94.dfsg-1)
forky: resolved (fixed in 0.94.dfsg-1)
sid: resolved (fixed in 0.94.dfsg-1)
trixie: resolved (fixed in 0.94.dfsg-1)
Red Hat
clamav: multiple security fixes in 0.94 (CVE-2008-1389, CVE-2008-3912, CVE-2008-3913, CVE-2008-3914)
vendor_redhat·CVSS 5.0
CVE-2008-1389 [MEDIUM] clamav: multiple security fixes in 0.94 (CVE-2008-1389, CVE-2008-3912, CVE-2008-3913, CVE-2008-3914)
clamav: multiple security fixes in 0.94 (CVE-2008-1389, CVE-2008-3912, CVE-2008-3913, CVE-2008-3914)
libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote attackers to cause a denial of service (application crash) via a malformed CHM file, related to an "invalid memory access."
No detection rules found.
No public exploits indexed.
http://kolab.org/security/kolab-vendor-notice-22.txthttp://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.htmlhttp://secunia.com/advisories/31906http://secunia.com/advisories/31982http://secunia.com/advisories/32030http://secunia.com/advisories/32222http://secunia.com/advisories/32424http://secunia.com/advisories/32699http://security.gentoo.org/glsa/glsa-200809-18.xmlhttp://sourceforge.net/project/shownotes.php?group_id=86638&release_id=623661http://support.apple.com/kb/HT3216http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLoghttp://www.debian.org/security/2008/dsa-1660http://www.mandriva.com/security/advisories?name=MDVSA-2008:189http://www.openwall.com/lists/oss-security/2008/09/03/2http://www.openwall.com/lists/oss-security/2008/09/04/13http://www.securityfocus.com/bid/31051http://www.securityfocus.com/bid/31681http://www.securitytracker.com/id?1020828http://www.vupen.com/english/advisories/2008/2564http://www.vupen.com/english/advisories/2008/2780https://exchange.xforce.ibmcloud.com/vulnerabilities/45057https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00332.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-November/msg00348.htmlhttps://wwws.clamav.net/bugzilla/show_bug.cgi?id=1141http://kolab.org/security/kolab-vendor-notice-22.txthttp://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.htmlhttp://secunia.com/advisories/31906http://secunia.com/advisories/31982http://secunia.com/advisories/32030http://secunia.com/advisories/32222http://secunia.com/advisories/32424http://secunia.com/advisories/32699http://security.gentoo.org/glsa/glsa-200809-18.xmlhttp://sourceforge.net/project/shownotes.php?group_id=86638&release_id=623661http://support.apple.com/kb/HT3216http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLoghttp://www.debian.org/security/2008/dsa-1660http://www.mandriva.com/security/advisories?name=MDVSA-2008:189http://www.openwall.com/lists/oss-security/2008/09/03/2http://www.openwall.com/lists/oss-security/2008/09/04/13http://www.securityfocus.com/bid/31051http://www.securityfocus.com/bid/31681http://www.securitytracker.com/id?1020828http://www.vupen.com/english/advisories/2008/2564http://www.vupen.com/english/advisories/2008/2780https://exchange.xforce.ibmcloud.com/vulnerabilities/45057https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00332.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-November/msg00348.htmlhttps://wwws.clamav.net/bugzilla/show_bug.cgi?id=1141
2008-09-11
Published