CVE-2005-3501: Medium severity clamav clamav vulnerability
The cabdfind function in cabd.c of the libmspack library (mspack) for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted CAB file that causes cabdfind to be called with a zero length.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3501?
CVE-2005-3501 has a medium severity rating due to its potential to cause a denial of service through an infinite loop when processing a crafted CAB file.
How do I fix CVE-2005-3501?
To fix CVE-2005-3501, upgrade ClamAV to version 0.87.1 or later, where the vulnerability has been addressed.
What versions of ClamAV are affected by CVE-2005-3501?
CVE-2005-3501 affects ClamAV versions up to 0.87, including various releases from 0.01 up to 0.86.1.
Can CVE-2005-3501 be exploited remotely?
Yes, CVE-2005-3501 can be exploited by remote attackers through specially crafted CAB files.
What type of vulnerability is CVE-2005-3501?
CVE-2005-3501 is classified as a denial of service (DoS) vulnerability.