CVE-2003-0946: High severity clam anti-virus clamav vulnerability
Format string vulnerability in clamav-milter for Clam AntiVirus 0.60 through 0.60p, and other versions before 0.65, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in the email address argument of a "MAIL FROM" command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco ClamAV (Clam AntiVirus clamav-milter)to a version that resolves this vulnerability.Fixed in 0.65
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0946?
CVE-2003-0946 has a medium severity rating due to the potential for denial of service and arbitrary code execution.
How do I fix CVE-2003-0946?
To fix CVE-2003-0946, upgrade to Clam AntiVirus version 0.65 or later, where the vulnerability has been patched.
Who is affected by CVE-2003-0946?
CVE-2003-0946 affects Clam AntiVirus versions 0.60 to 0.60p and earlier versions.
What causes the vulnerability in CVE-2003-0946?
The vulnerability in CVE-2003-0946 is caused by improper handling of format string specifiers in the 'MAIL FROM' command.
Can CVE-2003-0946 lead to data breaches?
Yes, CVE-2003-0946 can potentially lead to data breaches if an attacker successfully exploits the format string vulnerability.