CVE-2005-2920: Buffer Overflow
Published Sep 20, 2005
·Updated
Buffer overflow in libclamav/upx.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to execute arbitrary code via a crafted UPX packed executable.
Affected Software
17 affected components
Clam Anti-Virus clamav=0.70
Clam Anti-Virus clamav=0.71
Clam Anti-Virus clamav=0.72
Clam Anti-Virus clamav=0.73
Clam Anti-Virus clamav=0.74
Clam Anti-Virus clamav=0.75
Clam Anti-Virus clamav=0.75.1
Clam Anti-Virus clamav=0.80
Clam Anti-Virus clamav=0.81
Clam Anti-Virus clamav=0.82
Clam Anti-Virus clamav=0.83
Clam Anti-Virus clamav=0.84
Clam Anti-Virus clamav=0.85
Clam Anti-Virus clamav=0.85.1
Clam Anti-Virus clamav=0.86
Clam Anti-Virus clamav=0.86.1
Clam Anti-Virus clamav=0.86.2
Remediation
Patch Available
Event History
Sep 20, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2920?
CVE-2005-2920 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2005-2920?
To fix CVE-2005-2920, upgrade ClamAV to version 0.87 or later.
3
What versions of ClamAV are affected by CVE-2005-2920?
CVE-2005-2920 affects ClamAV versions prior to 0.87, including versions from 0.70 to 0.86.2.
4
Can CVE-2005-2920 be exploited remotely?
Yes, CVE-2005-2920 can be exploited remotely through crafted UPX packed executables.
5
What is CVE-2005-2920?
CVE-2005-2920 is a vulnerability in ClamAV that allows remote attackers to execute arbitrary code via a buffer overflow.