First published: Fri Feb 16 2007(Updated: )
Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV before 0.90 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the id MIME header parameter in a multi-part message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ClamXAV | =0.24 | |
ClamXAV | =0.20 | |
ClamXAV | =0.84 | |
ClamXAV | =0.80 | |
ClamXAV | =0.84_rc1 | |
ClamXAV | =0.15 | |
ClamXAV | =0.80_rc3 | |
ClamXAV | =0.80_rc4 | |
ClamXAV | =0.65 | |
ClamXAV | =0.75 | |
ClamXAV | =0.68 | |
ClamXAV | =0.71 | |
ClamXAV | =0.88.3 | |
ClamXAV | =0.86.1 | |
ClamXAV | =0.82 | |
ClamXAV | =0.88.1 | |
ClamXAV | =0.73 | |
ClamXAV | =0.72 | |
ClamXAV | =0.85.1 | |
ClamXAV | =0.87 | |
ClamXAV | =0.86_rc1 | |
ClamXAV | =0.85 | |
ClamXAV | =0.80_rc1 | |
ClamXAV | =0.74 | |
ClamXAV | =0.75.1 | |
ClamXAV | =0.86.2 | |
ClamXAV | =0.67 | |
ClamXAV | =0.81 | |
ClamXAV | =0.21 | |
ClamXAV | =0.81_rc1 | |
ClamXAV | =0.54 | |
ClamXAV | =0.53 | |
ClamXAV | =0.70 | |
ClamXAV | =0.60p | |
ClamXAV | =0.80_rc2 | |
ClamXAV | =0.60 | |
ClamXAV | =0.86 | |
ClamXAV | =0.83 | |
ClamXAV | =0.68.1 | |
ClamXAV | =0.88 | |
ClamXAV | =0.87.1 | |
ClamXAV | =0.88.4 | |
ClamXAV | =0.84_rc2 | |
ClamXAV | =0.51 | |
ClamXAV | <=0.88.6 | |
ClamXAV | =0.23 | |
ClamXAV | =0.52 | |
ClamXAV | =0.22 | |
ClamAV | <=0.88.6 | |
ClamAV | =0.15 | |
ClamAV | =0.20 | |
ClamAV | =0.21 | |
ClamAV | =0.22 | |
ClamAV | =0.23 | |
ClamAV | =0.24 | |
ClamAV | =0.51 | |
ClamAV | =0.52 | |
ClamAV | =0.53 | |
ClamAV | =0.54 | |
ClamAV | =0.60 | |
ClamAV | =0.60p | |
ClamAV | =0.65 | |
ClamAV | =0.67 | |
ClamAV | =0.68 | |
ClamAV | =0.68.1 | |
ClamAV | =0.70 | |
ClamAV | =0.71 | |
ClamAV | =0.72 | |
ClamAV | =0.73 | |
ClamAV | =0.74 | |
ClamAV | =0.75 | |
ClamAV | =0.75.1 | |
ClamAV | =0.80 | |
ClamAV | =0.80_rc1 | |
ClamAV | =0.80_rc2 | |
ClamAV | =0.80_rc3 | |
ClamAV | =0.80_rc4 | |
ClamAV | =0.81 | |
ClamAV | =0.81_rc1 | |
ClamAV | =0.82 | |
ClamAV | =0.83 | |
ClamAV | =0.84 | |
ClamAV | =0.84_rc1 | |
ClamAV | =0.84_rc2 | |
ClamAV | =0.85 | |
ClamAV | =0.85.1 | |
ClamAV | =0.86 | |
ClamAV | =0.86.1 | |
ClamAV | =0.86.2 | |
ClamAV | =0.86_rc1 | |
ClamAV | =0.87 | |
ClamAV | =0.87.1 | |
ClamAV | =0.88 | |
ClamAV | =0.88.1 | |
ClamAV | =0.88.3 | |
ClamAV | =0.88.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0898 is classified as a critical vulnerability due to its potential to allow remote attackers to overwrite arbitrary files.
To fix CVE-2007-0898, upgrade ClamAV to version 0.90 or higher as it contains patches that address this vulnerability.
Affected versions of ClamAV for CVE-2007-0898 include all versions prior to 0.90.
CVE-2007-0898 is a directory traversal vulnerability that exploits the handling of the id MIME header.
Any user or organization using the affected versions of ClamAV may be at risk if they process malicious multi-part messages.