CVE-2015-2221
published 2015-05-12CVE-2015-2221: ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted y0da cryptor file.
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.21%
86.9th percentile
ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted y0da cryptor file.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| clamav | clamav | <= 0.98.6 | — |
| clamav | clamav | >= 0 < 0.98.7+dfsg-1 | 0.98.7+dfsg-1 |
| clamav | clamav | >= 0 < 0.98.7+dfsg-1 | 0.98.7+dfsg-1 |
| clamav | clamav | >= 0 < 0.98.7+dfsg-1 | 0.98.7+dfsg-1 |
| clamav | clamav | >= 0 < 0.98.7+dfsg-1 | 0.98.7+dfsg-1 |
| debian | clamav | < clamav 0.98.7+dfsg-1 (bookworm) | clamav 0.98.7+dfsg-1 (bookworm) |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2015-05-05
CVE-2015-2170 ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: ClamAV could be made to crash or run programs if it processed a specially
crafted file.
It was discovered that ClamAV incorrectly handled certain malformed files.
A remote attacker could use this issue to cause ClamAV to crash, resulting
in a denial of service, or possibly execute arbitrary code.
In the default installation, attackers would be isolated by the ClamAV
AppArmor profile.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Debian
CVE-2015-2221: clamav - ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infin...
vendor_debian·2015·CVSS 5.0
CVE-2015-2221 [MEDIUM] CVE-2015-2221: clamav - ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infin...
ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted y0da cryptor file.
Scope: local
bookworm: resolved (fixed in 0.98.7+dfsg-1)
bullseye: resolved (fixed in 0.98.7+dfsg-1)
forky: resolved (fixed in 0.98.7+dfsg-1)
sid: resolved (fixed in 0.98.7+dfsg-1)
trixie: resolved (fixed in 0.98.7+dfsg-1)
GHSA
GHSA-67f8-82xm-cq7m: ClamAV before 0
ghsa_unreviewed·2022-05-17
CVE-2015-2221 [MEDIUM] GHSA-67f8-82xm-cq7m: ClamAV before 0
ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted y0da cryptor file.
OSV
CVE-2015-2221: ClamAV before 0
osv·2015-05-12·CVSS 5.0
CVE-2015-2221 [MEDIUM] CVE-2015-2221: ClamAV before 0
ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted y0da cryptor file.
No detection rules found.
No public exploits indexed.
http://blog.clamav.net/2015/04/clamav-0987-has-been-released.htmlhttp://lists.opensuse.org/opensuse-updates/2015-05/msg00024.htmlhttp://ubuntu.com/usn/usn-2594-1http://www.securityfocus.com/bid/74443https://security.gentoo.org/glsa/201512-08http://blog.clamav.net/2015/04/clamav-0987-has-been-released.htmlhttp://lists.opensuse.org/opensuse-updates/2015-05/msg00024.htmlhttp://ubuntu.com/usn/usn-2594-1http://www.securityfocus.com/bid/74443https://security.gentoo.org/glsa/201512-08
2015-05-12
Published