First published: Tue Sep 20 2005(Updated: )
libclamav/fsg.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to cause a denial of service (infinite loop) via a crafted FSG packed executable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ClamXAV | =0.70 | |
ClamXAV | =0.71 | |
ClamXAV | =0.72 | |
ClamXAV | =0.73 | |
ClamXAV | =0.74 | |
ClamXAV | =0.75 | |
ClamXAV | =0.75.1 | |
ClamXAV | =0.80 | |
ClamXAV | =0.81 | |
ClamXAV | =0.82 | |
ClamXAV | =0.83 | |
ClamXAV | =0.84 | |
ClamXAV | =0.85 | |
ClamXAV | =0.85.1 | |
ClamXAV | =0.86 | |
ClamXAV | =0.86.1 | |
ClamXAV | =0.86.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2919 is considered a medium severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2005-2919, update ClamAV to version 0.87 or later.
CVE-2005-2919 can be exploited by remote attackers sending specially crafted FSG packed executables.
CVE-2005-2919 affects ClamAV versions prior to 0.87, including versions from 0.70 to 0.86.2.
CVE-2005-2919 can lead to an infinite loop, causing a denial of service on systems running vulnerable versions of ClamAV.