CVE-2013-7087Improper Restriction of Operations within the Bounds of a Memory Buffer in Clamav

Severity
9.8CRITICALNVD
EPSS
0.5%
top 34.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 15
Latest updateMay 5

Description

ClamAV before 0.97.7 has WWPack corrupt heap memory

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDclamav/clamav< 0.97.7
debiandebian/clamav< clamav 0.97.7+dfsg-1 (bookworm)
Debianclamav/clamav< 0.97.7+dfsg-1+3

Also affects: Debian Linux 10.0, 8.0, 9.0, Fedora 17, 18

🔴Vulnerability Details

2
GHSA
GHSA-39x3-26gc-r96h: ClamAV before 02022-05-05
OSV
CVE-2013-7087: ClamAV before 02019-11-15

📋Vendor Advisories

1
Debian
CVE-2013-7087: clamav - ClamAV before 0.97.7 has WWPack corrupt heap memory2013

💬Community

1
Bugzilla
CVE-2013-7087 CVE-2013-7088 CVE-2013-7089 clamav: Multiple potential security issues fixed in 0.97.7 version2013-03-18