First published: Thu Jun 07 2007(Updated: )
unsp.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 does not properly calculate the end of a certain buffer, with unknown impact and remote attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ClamAV | =0.90.1 | |
ClamAV | =0.90 | |
ClamAV | =0.90.2 | |
ClamAV | =0.90_rc1.1 | |
ClamAV | =0.90_rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3023 is considered a vulnerability of unknown severity due to the lack of detailed impact information.
To fix CVE-2007-3023, upgrade ClamAV to version 0.90.3 or later.
CVE-2007-3023 affects ClamAV versions 0.90.1, 0.90, 0.90.2, 0.90_rc1.1, and 0.90_rc2.
Yes, CVE-2007-3023 has potential remote attack vectors, although the exact exploit mechanism is unknown.
There are no known workarounds for CVE-2007-3023; updating to a patched version is the recommended action.