First published: Tue Mar 30 2004(Updated: )
The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ClamXAV | =0.51 | |
ClamXAV | =0.52 | |
ClamXAV | =0.53 | |
ClamXAV | =0.54 | |
ClamXAV | =0.60 | |
ClamXAV | =0.65 | |
ClamXAV | =0.67 | |
ClamXAV | =0.68 | |
ClamXAV | =0.68.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1876 is a high-severity vulnerability that allows local users to execute arbitrary commands through shell metacharacters in file names.
To fix CVE-2004-1876, update Clam AntiVirus to version 0.70 or later, which resolves the vulnerability.
CVE-2004-1876 affects ClamAV versions 0.51 through 0.68.1.
An attacker can exploit CVE-2004-1876 to execute arbitrary commands on the system by using specially crafted file names.
Local users with access to the ClamAV daemon are impacted by CVE-2004-1876 due to the ability to execute arbitrary commands.