CVE-2011-2721
published 2011-08-05CVE-2011-2721: Off-by-one error in the cli_hm_scan function in matcher-hash.c in libclamav in ClamAV before 0.97.2 allows remote attackers to cause a denial of service…
PriorityP420medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.38%
87.5th percentile
Off-by-one error in the cli_hm_scan function in matcher-hash.c in libclamav in ClamAV before 0.97.2 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message that is not properly handled during certain hash calculations.
Affected
98 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| clamav | clamav | <= 0.97.1 | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ClamAV vulnerability
vendor_ubuntu·2011-07-28
CVE-2011-2721 ClamAV vulnerability
Title: ClamAV vulnerability
Summary: An attacker could send crafted input to ClamAV and cause it to
crash.
It was discovered that the hash processing code in libclamav improperly
handled messages with certain hashes. This could allow a remote attacker to
craft a document that could cause clamav to crash, resulting in a denial of
service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2011-2721: clamav - Off-by-one error in the cli_hm_scan function in matcher-hash.c in libclamav in C...
vendor_debian·2011·CVSS 5.0
CVE-2011-2721 [MEDIUM] CVE-2011-2721: clamav - Off-by-one error in the cli_hm_scan function in matcher-hash.c in libclamav in C...
Off-by-one error in the cli_hm_scan function in matcher-hash.c in libclamav in ClamAV before 0.97.2 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message that is not properly handled during certain hash calculations.
Scope: local
bookworm: resolved (fixed in 0.97.2+dfsg-1)
bullseye: resolved (fixed in 0.97.2+dfsg-1)
forky: resolved (fixed in 0.97.2+dfsg-1)
sid: resolved (fixed in 0.97.2+dfsg-1)
trixie: resolved (fixed in 0.97.2+dfsg-1)
GHSA
GHSA-x69w-v5wv-rxpx: Off-by-one error in the cli_hm_scan function in matcher-hash
ghsa_unreviewed·2022-05-17
CVE-2011-2721 [MEDIUM] GHSA-x69w-v5wv-rxpx: Off-by-one error in the cli_hm_scan function in matcher-hash
Off-by-one error in the cli_hm_scan function in matcher-hash.c in libclamav in ClamAV before 0.97.2 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message that is not properly handled during certain hash calculations.
OSV
CVE-2011-2721: Off-by-one error in the cli_hm_scan function in matcher-hash
osv·2011-08-05·CVSS 5.0
CVE-2011-2721 [MEDIUM] CVE-2011-2721: Off-by-one error in the cli_hm_scan function in matcher-hash
Off-by-one error in the cli_hm_scan function in matcher-hash.c in libclamav in ClamAV before 0.97.2 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message that is not properly handled during certain hash calculations.
No detection rules found.
No public exploits indexed.
http://git.clamav.net/gitweb?p=clamav-devel.git%3Ba=blob_plain%3Bf=ChangeLog%3Bhb=clamav-0.97.2http://git.clamav.net/gitweb?p=clamav-devel.git%3Ba=commit%3Bh=4842733eb3f09be61caeed83778bb6679141dbc5http://lists.fedoraproject.org/pipermail/package-announce/2011-November/068940.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-November/068941.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-November/068942.htmlhttp://secunia.com/advisories/45382http://secunia.com/advisories/46717http://securitytracker.com/id?1025858http://www.mandriva.com/security/advisories?name=MDVSA-2011:122http://www.openwall.com/lists/oss-security/2011/07/26/13http://www.openwall.com/lists/oss-security/2011/07/26/3http://www.osvdb.org/74181http://www.securityfocus.com/bid/48891http://www.ubuntu.com/usn/USN-1179-1https://bugzilla.novell.com/show_bug.cgi?id=708263https://bugzilla.redhat.com/show_bug.cgi?id=725694https://exchange.xforce.ibmcloud.com/vulnerabilities/68785https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2818http://git.clamav.net/gitweb?p=clamav-devel.git%3Ba=blob_plain%3Bf=ChangeLog%3Bhb=clamav-0.97.2http://git.clamav.net/gitweb?p=clamav-devel.git%3Ba=commit%3Bh=4842733eb3f09be61caeed83778bb6679141dbc5http://lists.fedoraproject.org/pipermail/package-announce/2011-November/068940.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-November/068941.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-November/068942.htmlhttp://secunia.com/advisories/45382http://secunia.com/advisories/46717http://securitytracker.com/id?1025858http://www.mandriva.com/security/advisories?name=MDVSA-2011:122http://www.openwall.com/lists/oss-security/2011/07/26/13http://www.openwall.com/lists/oss-security/2011/07/26/3http://www.osvdb.org/74181http://www.securityfocus.com/bid/48891http://www.ubuntu.com/usn/USN-1179-1https://bugzilla.novell.com/show_bug.cgi?id=708263https://bugzilla.redhat.com/show_bug.cgi?id=725694https://exchange.xforce.ibmcloud.com/vulnerabilities/68785https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2818
2011-08-05
Published