CVE-2008-3914
published 2008-09-11CVE-2008-3914: Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1)…
PriorityP434critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.58%
88.1th percentile
Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| clamav | clamav | <= 0.93.3 | — |
| clamav | clamav | >= 0 < 0.94.dfsg-1 | 0.94.dfsg-1 |
| clamav | clamav | >= 0 < 0.94.dfsg-1 | 0.94.dfsg-1 |
| clamav | clamav | >= 0 < 0.94.dfsg-1 | 0.94.dfsg-1 |
| clamav | clamav | >= 0 < 0.94.dfsg-1 | 0.94.dfsg-1 |
| debian | clamav | < clamav 0.94.dfsg-1 (bookworm) | clamav 0.94.dfsg-1 (bookworm) |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_msrc10.0CRITICAL
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3qxg-frxh-f5j5: Multiple unspecified vulnerabilities in ClamAV before 0
ghsa_unreviewed·2022-05-02
CVE-2008-3914 [HIGH] CWE-200 GHSA-3qxg-frxh-f5j5: Multiple unspecified vulnerabilities in ClamAV before 0
Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c.
OSV
CVE-2008-3914: Multiple unspecified vulnerabilities in ClamAV before 0
osv·2008-09-11·CVSS 10.0
CVE-2008-3914 [CRITICAL] CVE-2008-3914: Multiple unspecified vulnerabilities in ClamAV before 0
Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c.
Microsoft
CVE-2008-3914: NIST NVD Details: https://nvd
vendor_msrc·2020-10-13·CVSS 10.0
CVE-2008-3914 [CRITICAL] CVE-2008-3914: NIST NVD Details: https://nvd
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2008-3914
Mariner: Mariner
[email protected]: [email protected]
Exploit Status: DOS:N/A
Remediation: clamav
Debian
CVE-2008-3914: clamav - Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact a...
vendor_debian·2008·CVSS 10.0
CVE-2008-3914 [CRITICAL] CVE-2008-3914: clamav - Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact a...
Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c.
Scope: local
bookworm: resolved (fixed in 0.94.dfsg-1)
bullseye: resolved (fixed in 0.94.dfsg-1)
forky: resolved (fixed in 0.94.dfsg-1)
sid: resolved (fixed in 0.94.dfsg-1)
trixie: resolved (fixed in 0.94.dfsg-1)
Red Hat
clamav: multiple security fixes in 0.94 (CVE-2008-1389, CVE-2008-3912, CVE-2008-3913, CVE-2008-3914)
vendor_redhat·CVSS 5.0
CVE-2008-1389 [MEDIUM] clamav: multiple security fixes in 0.94 (CVE-2008-1389, CVE-2008-3912, CVE-2008-3913, CVE-2008-3914)
clamav: multiple security fixes in 0.94 (CVE-2008-1389, CVE-2008-3912, CVE-2008-3913, CVE-2008-3914)
libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote attackers to cause a denial of service (application crash) via a malformed CHM file, related to an "invalid memory access."
No detection rules found.
http://kolab.org/security/kolab-vendor-notice-22.txthttp://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.htmlhttp://secunia.com/advisories/31906http://secunia.com/advisories/31982http://secunia.com/advisories/32030http://secunia.com/advisories/32222http://secunia.com/advisories/32424http://secunia.com/advisories/32699http://security.gentoo.org/glsa/glsa-200809-18.xmlhttp://sourceforge.net/project/shownotes.php?group_id=86638&release_id=623661http://support.apple.com/kb/HT3216http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLoghttp://www.debian.org/security/2008/dsa-1660http://www.mandriva.com/security/advisories?name=MDVSA-2008:189http://www.openwall.com/lists/oss-security/2008/09/03/2http://www.openwall.com/lists/oss-security/2008/09/04/13http://www.securityfocus.com/bid/31051http://www.securityfocus.com/bid/31681http://www.securitytracker.com/id?1020828http://www.vupen.com/english/advisories/2008/2564http://www.vupen.com/english/advisories/2008/2780https://exchange.xforce.ibmcloud.com/vulnerabilities/45058https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00332.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-November/msg00348.htmlhttps://wwws.clamav.net/bugzilla/show_bug.cgi?id=1141http://kolab.org/security/kolab-vendor-notice-22.txthttp://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.htmlhttp://secunia.com/advisories/31906http://secunia.com/advisories/31982http://secunia.com/advisories/32030http://secunia.com/advisories/32222http://secunia.com/advisories/32424http://secunia.com/advisories/32699http://security.gentoo.org/glsa/glsa-200809-18.xmlhttp://sourceforge.net/project/shownotes.php?group_id=86638&release_id=623661http://support.apple.com/kb/HT3216http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLoghttp://www.debian.org/security/2008/dsa-1660http://www.mandriva.com/security/advisories?name=MDVSA-2008:189http://www.openwall.com/lists/oss-security/2008/09/03/2http://www.openwall.com/lists/oss-security/2008/09/04/13http://www.securityfocus.com/bid/31051http://www.securityfocus.com/bid/31681http://www.securitytracker.com/id?1020828http://www.vupen.com/english/advisories/2008/2564http://www.vupen.com/english/advisories/2008/2780https://exchange.xforce.ibmcloud.com/vulnerabilities/45058https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00332.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-November/msg00348.htmlhttps://wwws.clamav.net/bugzilla/show_bug.cgi?id=1141
2008-09-11
Published