CVE-2005-2450: Integer Overflow
Published Aug 3, 2005
·Updated
Multiple integer overflows in the (1) TNEF, (2) CHM, or (3) FSG file format processors in libclamav for Clam AntiVirus (ClamAV) 0.86.1 and earlier allow remote attackers to gain privileges via a crafted e-mail message.
Affected Software
3 affected components
Clam Anti-Virus clamav=0.85
Clam Anti-Virus clamav=0.85.1
Clam Anti-Virus clamav=0.86
Remediation
Event History
Aug 3, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2450?
CVE-2005-2450 has a high severity rating due to the potential for remote code execution and privilege escalation.
2
How do I fix CVE-2005-2450?
To fix CVE-2005-2450, update ClamAV to version 0.86.1 or later, which addresses the identified vulnerabilities.
3
What software versions are affected by CVE-2005-2450?
CVE-2005-2450 affects ClamAV versions 0.85, 0.85.1, and 0.86.
4
Can CVE-2005-2450 be exploited remotely?
Yes, CVE-2005-2450 can be exploited remotely through specially crafted email messages.
5
What type of vulnerability is CVE-2005-2450?
CVE-2005-2450 is categorized as an integer overflow vulnerability, which can lead to memory corruption.