CVE-2008-0318: Buffer Overflow
Published Feb 12, 2008
·Updated
Integer overflow in the cliscanpe function in libclamav in ClamAV before 0.92.1, as used in clamd, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Petite packed PE file, which triggers a heap-based buffer overflow.
Affected Software
1 affected component
Clam Anti-Virus clamav<=0.92
Remediation
Event History
Feb 12, 2008
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0318?
CVE-2008-0318 has a high severity rating due to the potential for denial of service and possible arbitrary code execution.
2
How do I fix CVE-2008-0318?
To fix CVE-2008-0318, you should upgrade ClamAV to version 0.92.1 or later.
3
What causes the vulnerability in CVE-2008-0318?
The vulnerability in CVE-2008-0318 is caused by an integer overflow in the cli_scanpe function within libclamav.
4
Which versions of ClamAV are affected by CVE-2008-0318?
CVE-2008-0318 affects ClamAV versions up to and including 0.92.
5
What type of attack can exploit CVE-2008-0318?
CVE-2008-0318 can be exploited by remote attackers through a crafted Petite packed PE file.