First published: Tue Nov 18 2003(Updated: )
Format string vulnerability in clamav-milter for Clam AntiVirus 0.60 through 0.60p, and other versions before 0.65, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in the email address argument of a "MAIL FROM" command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ClamAV | =0.60p | |
ClamAV | =0.60 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0946 has a medium severity rating due to the potential for denial of service and arbitrary code execution.
To fix CVE-2003-0946, upgrade to Clam AntiVirus version 0.65 or later, where the vulnerability has been patched.
CVE-2003-0946 affects Clam AntiVirus versions 0.60 to 0.60p and earlier versions.
The vulnerability in CVE-2003-0946 is caused by improper handling of format string specifiers in the 'MAIL FROM' command.
Yes, CVE-2003-0946 can potentially lead to data breaches if an attacker successfully exploits the format string vulnerability.