CVE-2004-1876: Medium severity Clam Anti-Virus clamav vulnerability
Published Mar 30, 2004
·Updated
The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name.
Affected Software
9 affected components
Clam Anti-Virus clamav=0.65
Clam Anti-Virus clamav=0.68
Clam Anti-Virus clamav=0.67
Clam Anti-Virus clamav=0.54
Clam Anti-Virus clamav=0.53
Clam Anti-Virus clamav=0.60
Clam Anti-Virus clamav=0.68.1
Clam Anti-Virus clamav=0.51
Clam Anti-Virus clamav=0.52
Remediation
Patch Available
Patch Available
Patch Available
Event History
Mar 30, 2004
CVE Published
05:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1876?
CVE-2004-1876 is a high-severity vulnerability that allows local users to execute arbitrary commands through shell metacharacters in file names.
2
How do I fix CVE-2004-1876?
To fix CVE-2004-1876, update Clam AntiVirus to version 0.70 or later, which resolves the vulnerability.
3
Which versions of ClamAV are affected by CVE-2004-1876?
CVE-2004-1876 affects ClamAV versions 0.51 through 0.68.1.
4
What kind of attack can exploit CVE-2004-1876?
An attacker can exploit CVE-2004-1876 to execute arbitrary commands on the system by using specially crafted file names.
5
Who is impacted by CVE-2004-1876?
Local users with access to the ClamAV daemon are impacted by CVE-2004-1876 due to the ability to execute arbitrary commands.