CVE-2007-4560: OS Command Injection
Published Aug 28, 2007
·Updated
clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharacters that are used in a certain popen call, involving the "recipient field of sendmail."
Affected Software
1 affected component
Clam Anti-Virus clamav<=0.91.1
Remediation
Patch Available
Event History
Aug 28, 2007
CVE Published
01:17 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4560?
CVE-2007-4560 is considered a critical vulnerability allowing remote code execution.
2
How do I fix CVE-2007-4560?
To fix CVE-2007-4560, upgrade ClamAV to version 0.91.2 or later.
3
What systems are affected by CVE-2007-4560?
CVE-2007-4560 affects ClamAV versions prior to 0.91.2, particularly when run in black hole mode.
4
What types of attacks are possible with CVE-2007-4560?
CVE-2007-4560 allows remote attackers to execute arbitrary commands on the vulnerable system.
5
Is there a workaround for CVE-2007-4560 if I cannot update?
A potential workaround for CVE-2007-4560 is to avoid using black hole mode with ClamAV.