CVE-2005-1922: Medium severity clam anti-virus clamav vulnerability
Published Jun 30, 2005
·Updated
The MS-Expand file handling in Clam AntiVirus (ClamAV) before 0.86 allows remote attackers to cause a denial of service (file descriptor and memory consumption) via a crafted file that causes repeated errors in the climsexpand function.
Affected Software
7 affected components
Clam Anti-Virus clamav=0.84_rc1
Clam Anti-Virus clamav=0.82
Clam Anti-Virus clamav=0.85.1
Clam Anti-Virus clamav=0.85
Clam Anti-Virus clamav=0.81
Clam Anti-Virus clamav=0.83
Clam Anti-Virus clamav=0.84_rc2
Remediation
Event History
Jun 30, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1922?
CVE-2005-1922 has a severity rating that indicates it can lead to denial of service due to resource exhaustion.
2
How do I fix CVE-2005-1922?
To fix CVE-2005-1922, update Clam AntiVirus to version 0.86 or later.
3
What versions of ClamAV are affected by CVE-2005-1922?
CVE-2005-1922 affects ClamAV versions 0.81 through 0.85.1.
4
What type of attack is related to CVE-2005-1922?
CVE-2005-1922 is related to a denial of service attack due to crafted MS-Expand files.
5
Can CVE-2005-1922 impact system performance?
Yes, CVE-2005-1922 can significantly impact system performance by causing file descriptor and memory consumption.