CVE-2008-6680
published 2009-04-08CVE-2008-6680: libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.
PriorityP418medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.72%
88.6th percentile
libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| clamav | clamav | <= 0.94.2 | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | >= 0 < 0.95.1+dfsg-1 | 0.95.1+dfsg-1 |
| clamav | clamav | >= 0 < 0.95.1+dfsg-1 | 0.95.1+dfsg-1 |
| clamav | clamav | >= 0 < 0.95.1+dfsg-1 | 0.95.1+dfsg-1 |
| clamav | clamav | >= 0 < 0.95.1+dfsg-1 | 0.95.1+dfsg-1 |
| debian | clamav | < clamav 0.95.1+dfsg-1 (bookworm) | clamav 0.95.1+dfsg-1 (bookworm) |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8gp4-6h2g-rfv6: libclamav/pe
ghsa_unreviewed·2022-05-17
CVE-2008-6680 [MEDIUM] GHSA-8gp4-6h2g-rfv6: libclamav/pe
libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.
OSV
CVE-2008-6680: libclamav/pe
osv·2009-04-08·CVSS 5.0
CVE-2008-6680 [MEDIUM] CVE-2008-6680: libclamav/pe
libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2009-04-07·CVSS 5.0
CVE-2008-6680 [MEDIUM] ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: ClamAV vulnerabilities
It was discovered that ClamAV did not properly verify its input when
processing TAR archives. A remote attacker could send a specially crafted
TAR file and cause a denial of service via infinite loop. (CVE-2009-1270)
It was discovered that ClamAV did not properly validate Portable Executable
(PE) files. A remote attacker could send a crafted PE file and cause a
denial of service (divide by zero). (CVE-2008-6680)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2008-6680: clamav - libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial o...
vendor_debian·2008·CVSS 5.0
CVE-2008-6680 [MEDIUM] CVE-2008-6680: clamav - libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial o...
libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.
Scope: local
bookworm: resolved (fixed in 0.95.1+dfsg-1)
bullseye: resolved (fixed in 0.95.1+dfsg-1)
forky: resolved (fixed in 0.95.1+dfsg-1)
sid: resolved (fixed in 0.95.1+dfsg-1)
trixie: resolved (fixed in 0.95.1+dfsg-1)
Red Hat
clamav: security fixes in upstream 0.95 (CVE-2008-6680, CVE-2009-1270)
vendor_redhat·CVSS 5.0
CVE-2009-1270 [MEDIUM] clamav: security fixes in upstream 0.95 (CVE-2008-6680, CVE-2009-1270)
clamav: security fixes in upstream 0.95 (CVE-2008-6680, CVE-2009-1270)
libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.
Red Hat
clamav: security fixes in upstream 0.95 (CVE-2008-6680, CVE-2009-1270)
vendor_redhat·CVSS 5.0
CVE-2008-6680 [MEDIUM] clamav: security fixes in upstream 0.95 (CVE-2008-6680, CVE-2009-1270)
clamav: security fixes in upstream 0.95 (CVE-2008-6680, CVE-2009-1270)
libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.
Red Hat
clamav: security fixes in upstream 0.95 (CVE-2008-6680, CVE-2009-1270)
vendor_redhat·CVSS 5.0
CVE-2009-1241 [MEDIUM] clamav: security fixes in upstream 0.95 (CVE-2008-6680, CVE-2009-1270)
clamav: security fixes in upstream 0.95 (CVE-2008-6680, CVE-2009-1270)
Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive.
No detection rules found.
No public exploits indexed.
Bugzilla
Clam AntiVirus: Multiple vulnerabilities
bugzilla·2009-09-09·CVSS 5.0
[MEDIUM] Clam AntiVirus: Multiple vulnerabilities
Clam AntiVirus: Multiple vulnerabilities
Personal comment
Probably SELINUX targeted policy, and Selinux Memory check, mitigate this
but it necessary to upgrade anyway. I open here because this is a security bug and not a generic bug.
Synopsis
Multiple vulnerabilities in ClamAV allow for the remote execution of arbitrary code or Denial of Service.
2. Impact Information
Background
Clam AntiVirus (short: ClamAV) is an anti-virus toolkit for UNIX, designed especially for e-mail scanning on mail gateways.
Description
Multiple vulnerabilities have been found in ClamAV:
* The vendor reported a Divide-by-zero error in the PE ("Portable Executable"; Windows .exe) file handling of ClamAV (CVE-2008-6680).
* Jeffrey Thomas Peckham found a flaw in libclamav/untar.c, possibly resulting in an
Bugzilla
clamav: security fixes in upstream 0.95 (CVE-2008-6680, CVE-2009-1270)
bugzilla·2009-04-09·CVSS 5.0
CVE-2008-6680 [MEDIUM] clamav: security fixes in upstream 0.95 (CVE-2008-6680, CVE-2009-1270)
clamav: security fixes in upstream 0.95 (CVE-2008-6680, CVE-2009-1270)
Upstream clamav version 0.95 fixes few security issues:
CVE-2008-6680:
libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause
a denial of service (crash) via a crafted EXE file that triggers a
divide-by-zero error.
Upstream bug:
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1335
Upstream fix:
svn diff -c 4980 http://svn.clamav.net/svn/clamav-devel/
CVE-2009-1270:
libclamav/untar.c in ClamAV before 0.95 allows remote attackers to
cause a denial of service (infinite loop) via a crafted file that
causes (1) clamd and (2) clamscan to hang.
Upstream bug:
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1462
Upstream fix:
svn diff -c 4981 http://svn.clamav.net/svn/clamav-devel/
Discussion:
For the
http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.htmlhttp://secunia.com/advisories/34716http://secunia.com/advisories/36701http://support.apple.com/kb/HT3865http://www.debian.org/security/2009/dsa-1771http://www.mandriva.com/security/advisories?name=MDVSA-2009:097http://www.openwall.com/lists/oss-security/2009/04/07/6http://www.securityfocus.com/bid/34357http://www.ubuntu.com/usn/usn-754-1http://www.vupen.com/english/advisories/2009/0934https://exchange.xforce.ibmcloud.com/vulnerabilities/49845https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1335http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.htmlhttp://secunia.com/advisories/34716http://secunia.com/advisories/36701http://support.apple.com/kb/HT3865http://www.debian.org/security/2009/dsa-1771http://www.mandriva.com/security/advisories?name=MDVSA-2009:097http://www.openwall.com/lists/oss-security/2009/04/07/6http://www.securityfocus.com/bid/34357http://www.ubuntu.com/usn/usn-754-1http://www.vupen.com/english/advisories/2009/0934https://exchange.xforce.ibmcloud.com/vulnerabilities/49845https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1335
2009-04-08
Published