CVE-2007-1997: Buffer Overflow
Published Apr 16, 2007
·Updated
Integer signedness error in the (1) cabunstore and (2) cabextract functions in libclamav/cab.c in Clam AntiVirus (ClamAV) before 0.90.2 allow remote attackers to execute arbitrary code via a crafted CHM file that contains a negative integer, which passes a signed comparison and leads to a stack-based buffer overflow.
Affected Software
6 affected components
Clam Anti-Virus clamav=0.90.1
Clam Anti-Virus clamav=0.90
Clam Anti-Virus clamav=0.90.2
Clam Anti-Virus clamav=0.90_rc1.1
Clam Anti-Virus clamav=0.90_rc2
Clam Anti-Virus clamav=0.90_rc3
Remediation
Patch Available
Patch Available
Event History
Apr 16, 2007
CVE Published
09:19 PM
Apr 17, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1997?
CVE-2007-1997 has a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2007-1997?
To fix CVE-2007-1997, upgrade ClamAV to version 0.90.2 or later.
3
What types of files are exploited in CVE-2007-1997?
CVE-2007-1997 exploits crafted CHM files that contain negative integers.
4
Which versions of ClamAV are affected by CVE-2007-1997?
CVE-2007-1997 affects ClamAV versions 0.90 and earlier, including 0.90.1.
5
Can CVE-2007-1997 be exploited remotely?
Yes, CVE-2007-1997 can be exploited remotely by attackers using specially crafted files.