CVE-2005-1923: Low severity clam anti-virus clamav vulnerability
The ENSUREBITS macro in mszipd.c for Clam AntiVirus (ClamAV) 0.83, and other versions vefore 0.86, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a cabinet (CAB) file with the cffileFolderOffset field set to 0xff, which causes a zero-length read.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1923?
CVE-2005-1923 is classified as a denial of service vulnerability due to CPU consumption caused by an infinite loop.
How do I fix CVE-2005-1923?
To fix CVE-2005-1923, upgrade ClamAV to version 0.86 or later.
Which versions of ClamAV are affected by CVE-2005-1923?
CVE-2005-1923 affects ClamAV versions 0.83, 0.84_rc1, 0.84_rc2, 0.85, and 0.85.1.
Can CVE-2005-1923 be exploited remotely?
Yes, CVE-2005-1923 can be exploited remotely by sending a specially crafted CAB file.
What impact does CVE-2005-1923 have on systems running ClamAV?
The impact of CVE-2005-1923 is significant as it leads to high CPU consumption potentially causing system unresponsiveness.