First published: Fri Feb 16 2007(Updated: )
Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ClamAV ClamAV | <0.90 | |
Apple Mac OS X Server | <10.4.11 | |
Debian | =3.1 | |
ClamAV | <=0.22 | |
ClamAV | <=0.80_rc2 | |
ClamAV | <=0.87 | |
ClamAV | <=0.84_rc2 | |
ClamAV | <=0.60 | |
ClamAV | <=0.20 | |
ClamAV | <=0.87.1 | |
ClamAV | <=0.52 | |
ClamAV | <=0.67 | |
ClamAV | <=0.80 | |
ClamAV | <=0.74 | |
ClamAV | <=0.73 | |
ClamAV | <=0.68.1 | |
ClamAV | <=0.23 | |
ClamAV | <=0.88.1 | |
ClamAV | <=0.21 | |
ClamAV | <=0.85 | |
ClamAV | <=0.88.4 | |
ClamAV | <=0.80_rc4 | |
ClamAV | <=0.88 | |
ClamAV | <=0.75 | |
ClamAV | <=0.65 | |
ClamAV | <=0.75.1 | |
ClamAV | <=0.80_rc1 | |
ClamAV | <=0.51 | |
ClamAV | <=0.83 | |
ClamAV | <=0.72 | |
ClamAV | <=0.53 | |
ClamAV | <=0.82 | |
ClamAV | <=0.71 | |
ClamAV | <=0.15 | |
ClamAV | <=0.54 | |
ClamAV | <=0.86.1 | |
ClamAV | <=0.68 | |
ClamAV | <=0.86_rc1 | |
ClamAV | <=0.81 | |
ClamAV | <=0.84_rc1 | |
ClamAV | <=0.84 | |
ClamAV | <=0.70 | |
ClamAV | <=0.86.2 | |
ClamAV | <=0.80_rc3 | |
ClamAV | <=0.60p | |
ClamAV | <=0.88.3 | |
ClamAV | <=0.24 | |
ClamAV | <=0.88.6 | |
ClamAV | <=0.86 | |
ClamAV | <=0.85.1 | |
ClamAV | <=0.81_rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.