CVE-2005-3500: Medium severity clam anti-virus clamav vulnerability
The tnefattachment function in tnef.c for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via a crafted value in a CAB file that causes ClamAV to repeatedly scan the same block.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3500?
CVE-2005-3500 is considered to have a high severity due to its potential for causing denial of service through infinite loops and memory exhaustion.
How do I fix CVE-2005-3500?
To mitigate CVE-2005-3500, upgrade ClamAV to version 0.87.1 or later, which includes a patch for this vulnerability.
What versions of ClamAV are affected by CVE-2005-3500?
CVE-2005-3500 affects multiple versions of ClamAV, including versions 0.15 through 0.86.2.
What impact does CVE-2005-3500 have on systems?
CVE-2005-3500 can lead to denial of service, causing systems to become unresponsive due to excessive scanning of crafted CAB files.
Who can exploit CVE-2005-3500?
CVE-2005-3500 can be exploited by remote attackers who can send crafted CAB files to the vulnerable ClamAV instance.