CVE-2004-0270: Medium severity clam anti-virus clamav vulnerability
Published Sep 1, 2004
·Updated
libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail message with an invalid line length (e.g., a lowercase character), which causes an assert error in clamd that terminates the calling program.
Affected Software
1 affected component
Clam Anti-Virus clamav=0.65
Remediation
Patch Available
Event History
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0270?
CVE-2004-0270 is classified as a denial of service vulnerability.
2
How do I fix CVE-2004-0270?
To fix CVE-2004-0270, upgrade Clam AntiVirus to a version later than 0.65.
3
Which version of Clam AntiVirus is affected by CVE-2004-0270?
Clam AntiVirus version 0.65 is affected by CVE-2004-0270.
4
What type of attack is possible with CVE-2004-0270?
CVE-2004-0270 allows remote attackers to send a specially crafted uuencoded email that causes a program crash.
5
What happens when exploit CVE-2004-0270 is successfully executed?
The successful exploit of CVE-2004-0270 can terminate the clamd process, leading to service disruption.