CVE-2007-3023: Critical severity Clam Anti-Virus clamav vulnerability
Published Jun 7, 2007
·Updated
unsp.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 does not properly calculate the end of a certain buffer, with unknown impact and remote attack vectors.
Affected Software
5 affected components
Clam Anti-Virus clamav=0.90.1
Clam Anti-Virus clamav=0.90
Clam Anti-Virus clamav=0.90.2
Clam Anti-Virus clamav=0.90_rc1.1
Clam Anti-Virus clamav=0.90_rc2
Remediation
Patch Available
Event History
Jun 7, 2007
CVE Published
09:30 PM
Jun 8, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3023?
CVE-2007-3023 is considered a vulnerability of unknown severity due to the lack of detailed impact information.
2
How do I fix CVE-2007-3023?
To fix CVE-2007-3023, upgrade ClamAV to version 0.90.3 or later.
3
What versions of ClamAV are affected by CVE-2007-3023?
CVE-2007-3023 affects ClamAV versions 0.90.1, 0.90, 0.90.2, 0.90_rc1.1, and 0.90_rc2.
4
Can CVE-2007-3023 be exploited remotely?
Yes, CVE-2007-3023 has potential remote attack vectors, although the exact exploit mechanism is unknown.
5
Is there a workaround for CVE-2007-3023?
There are no known workarounds for CVE-2007-3023; updating to a patched version is the recommended action.