CVE-2005-2919: Medium severity clam anti-virus clamav vulnerability
Published Sep 20, 2005
·Updated
libclamav/fsg.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to cause a denial of service (infinite loop) via a crafted FSG packed executable.
Affected Software
17 affected components
Clam Anti-Virus clamav=0.84
Clam Anti-Virus clamav=0.80
Clam Anti-Virus clamav=0.75
Clam Anti-Virus clamav=0.71
Clam Anti-Virus clamav=0.86.1
Clam Anti-Virus clamav=0.82
Clam Anti-Virus clamav=0.73
Clam Anti-Virus clamav=0.72
Clam Anti-Virus clamav=0.85.1
Clam Anti-Virus clamav=0.85
Clam Anti-Virus clamav=0.74
Clam Anti-Virus clamav=0.75.1
Clam Anti-Virus clamav=0.86.2
Clam Anti-Virus clamav=0.81
Clam Anti-Virus clamav=0.70
Clam Anti-Virus clamav=0.86
Clam Anti-Virus clamav=0.83
Remediation
Event History
Sep 20, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2919?
CVE-2005-2919 is considered a medium severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2005-2919?
To fix CVE-2005-2919, update ClamAV to version 0.87 or later.
3
What types of attacks can exploit CVE-2005-2919?
CVE-2005-2919 can be exploited by remote attackers sending specially crafted FSG packed executables.
4
Which versions of ClamAV are affected by CVE-2005-2919?
CVE-2005-2919 affects ClamAV versions prior to 0.87, including versions from 0.70 to 0.86.2.
5
What impact does CVE-2005-2919 have on systems running vulnerable versions of ClamAV?
CVE-2005-2919 can lead to an infinite loop, causing a denial of service on systems running vulnerable versions of ClamAV.