CVE-2005-0218: Medium severity clam anti-virus clamav vulnerability
Published Feb 6, 2005
·Updated
ClamAV 0.80 and earlier allows remote attackers to bypass virus scanning via a base64 encoded image in a data: (RFC 2397) URL.
Affected Software
10 affected components
Clam Anti-Virus clamav=0.51
Clam Anti-Virus clamav=0.52
Clam Anti-Virus clamav=0.53
Clam Anti-Virus clamav=0.54
Clam Anti-Virus clamav=0.60
Clam Anti-Virus clamav=0.65
Clam Anti-Virus clamav=0.67
Clam Anti-Virus clamav=0.68
Clam Anti-Virus clamav=0.68.1
Clam Anti-Virus clamav=0.80
Remediation
Patch Available
Event History
Feb 6, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the nature of CVE-2005-0218?
CVE-2005-0218 allows remote attackers to bypass virus scanning in ClamAV by using a base64 encoded image in a data URL.
2
Which versions of ClamAV are affected by CVE-2005-0218?
CVE-2005-0218 affects ClamAV versions 0.51 and earlier, including 0.52, 0.53, 0.54, 0.60, 0.65, 0.67, 0.68, and 0.68.1.
3
How can I patch CVE-2005-0218 in ClamAV?
To fix CVE-2005-0218, upgrade ClamAV to version 0.81 or later, which addresses this vulnerability.
4
What risks does CVE-2005-0218 pose to systems using ClamAV?
CVE-2005-0218 poses a risk of malware being delivered undetected, potentially allowing malicious content to execute on a system.
5
Is there a workaround for CVE-2005-0218 in vulnerable versions of ClamAV?
There are no official workarounds for CVE-2005-0218; the best approach is to upgrade to a secure version.