First published: Thu Jun 30 2005(Updated: )
The MS-Expand file handling in Clam AntiVirus (ClamAV) before 0.86 allows remote attackers to cause a denial of service (file descriptor and memory consumption) via a crafted file that causes repeated errors in the cli_msexpand function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ClamXAV | =0.81 | |
ClamXAV | =0.82 | |
ClamXAV | =0.83 | |
ClamXAV | =0.84_rc1 | |
ClamXAV | =0.84_rc2 | |
ClamXAV | =0.85 | |
ClamXAV | =0.85.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1922 has a severity rating that indicates it can lead to denial of service due to resource exhaustion.
To fix CVE-2005-1922, update Clam AntiVirus to version 0.86 or later.
CVE-2005-1922 affects ClamAV versions 0.81 through 0.85.1.
CVE-2005-1922 is related to a denial of service attack due to crafted MS-Expand files.
Yes, CVE-2005-1922 can significantly impact system performance by causing file descriptor and memory consumption.