CVE-2007-3123: Buffer Overflow
Published Jun 7, 2007
·Updated
unrar.c in libclamav in ClamAV before 0.90.3 and 0.91 before 0.91rc1 allows remote attackers to cause a denial of service (core dump) via a crafted RAR file with a modified vmcodesize value, which triggers a heap-based buffer overflow.
Affected Software
6 affected components
Clam Anti-Virus clamav=0.90.1
Clam Anti-Virus clamav=0.90
Clam Anti-Virus clamav=0.90.2
Clam Anti-Virus clamav=0.90_rc1.1
Clam Anti-Virus clamav=0.90_rc2
Clam Anti-Virus clamav=0.90_rc3
Remediation
Patch Available
Event History
Jun 7, 2007
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3123?
CVE-2007-3123 has a severity rating that indicates it can lead to denial of service due to a heap-based buffer overflow.
2
How do I fix CVE-2007-3123?
To fix CVE-2007-3123, update ClamAV to version 0.90.3 or later.
3
What versions of ClamAV are affected by CVE-2007-3123?
CVE-2007-3123 affects ClamAV versions 0.90 through 0.90_rc3, including 0.90.1 and 0.90.2.
4
Can exploiting CVE-2007-3123 impact system performance?
Yes, exploiting CVE-2007-3123 can cause a denial of service, negatively impacting system performance.
5
Is CVE-2007-3123 a remote vulnerability?
Yes, CVE-2007-3123 allows remote attackers to exploit the vulnerability via crafted RAR files.