First published: Tue Aug 28 2007(Updated: )
clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharacters that are used in a certain popen call, involving the "recipient field of sendmail."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ClamAV | <=0.91.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4560 is considered a critical vulnerability allowing remote code execution.
To fix CVE-2007-4560, upgrade ClamAV to version 0.91.2 or later.
CVE-2007-4560 affects ClamAV versions prior to 0.91.2, particularly when run in black hole mode.
CVE-2007-4560 allows remote attackers to execute arbitrary commands on the vulnerable system.
A potential workaround for CVE-2007-4560 is to avoid using black hole mode with ClamAV.