CVE-2005-3303: High severity clam anti-virus clamav vulnerability
Published Nov 5, 2005
·Updated
The FSG unpacker (fsg.c) in Clam AntiVirus (ClamAV) 0.80 through 0.87 allows remote attackers to cause "memory corruption" and execute arbitrary code via a crafted FSG 1.33 file.
Affected Software
11 affected components
Clam Anti-Virus clamav=0.80
Clam Anti-Virus clamav=0.81
Clam Anti-Virus clamav=0.82
Clam Anti-Virus clamav=0.83
Clam Anti-Virus clamav=0.84
Clam Anti-Virus clamav=0.85
Clam Anti-Virus clamav=0.85.1
Clam Anti-Virus clamav=0.86
Clam Anti-Virus clamav=0.86.1
Clam Anti-Virus clamav=0.86.2
Clam Anti-Virus clamav=0.87
Remediation
Patch Available
Patch Available
Event History
Nov 5, 2005
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3303?
CVE-2005-3303 is considered a critical vulnerability due to the potential for remote code execution and memory corruption.
2
How do I fix CVE-2005-3303?
To fix CVE-2005-3303, you should upgrade ClamAV to version 0.88 or later, which addresses this vulnerability.
3
Which versions of ClamAV are affected by CVE-2005-3303?
CVE-2005-3303 affects ClamAV versions 0.80 through 0.87.
4
Can CVE-2005-3303 be exploited remotely?
Yes, CVE-2005-3303 can be exploited by remote attackers via crafted FSG 1.33 files.
5
What type of attack does CVE-2005-3303 facilitate?
CVE-2005-3303 facilitates memory corruption attacks, potentially allowing attackers to execute arbitrary code.