CVE-2007-3122: Medium severity Clam Anti-Virus clamav vulnerability
Published Jun 7, 2007
·Updated
The parsing engine in ClamAV before 0.90.3 and 0.91 before 0.91rc1 allows remote attackers to bypass scanning via a RAR file with a header flag value of 10, which can be processed by WinRAR.
Affected Software
6 affected components
Clam Anti-Virus clamav=0.90
Clam Anti-Virus clamav=0.90.1
Clam Anti-Virus clamav=0.90.2
Clam Anti-Virus clamav=0.90_rc1.1
Clam Anti-Virus clamav=0.90_rc2
Clam Anti-Virus clamav=0.90_rc3
Remediation
Patch Available
Event History
Jun 7, 2007
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3122?
The severity of CVE-2007-3122 is classified as medium due to its ability to allow remote attackers to bypass scanning.
2
How do I fix CVE-2007-3122?
To fix CVE-2007-3122, upgrade ClamAV to version 0.90.3 or later.
3
Which versions of ClamAV are affected by CVE-2007-3122?
CVE-2007-3122 affects ClamAV versions 0.90, 0.90.1, 0.90.2, and pre-release versions up to 0.91rc1.
4
What type of attack does CVE-2007-3122 enable?
CVE-2007-3122 enables remote attackers to evade detection by exploiting a RAR file with a specific header flag.
5
Is there a workaround for CVE-2007-3122?
There is no specific workaround for CVE-2007-3122 other than upgrading to a patched version.