First published: Sun Feb 06 2005(Updated: )
ClamAV 0.80 and earlier allows remote attackers to bypass virus scanning via a base64 encoded image in a data: (RFC 2397) URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ClamXAV | =0.51 | |
ClamXAV | =0.52 | |
ClamXAV | =0.53 | |
ClamXAV | =0.54 | |
ClamXAV | =0.60 | |
ClamXAV | =0.65 | |
ClamXAV | =0.67 | |
ClamXAV | =0.68 | |
ClamXAV | =0.68.1 | |
ClamXAV | =0.80 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0218 allows remote attackers to bypass virus scanning in ClamAV by using a base64 encoded image in a data URL.
CVE-2005-0218 affects ClamAV versions 0.51 and earlier, including 0.52, 0.53, 0.54, 0.60, 0.65, 0.67, 0.68, and 0.68.1.
To fix CVE-2005-0218, upgrade ClamAV to version 0.81 or later, which addresses this vulnerability.
CVE-2005-0218 poses a risk of malware being delivered undetected, potentially allowing malicious content to execute on a system.
There are no official workarounds for CVE-2005-0218; the best approach is to upgrade to a secure version.