First published: Mon Apr 14 2008(Updated: )
Buffer overflow in the cli_scanpe function in libclamav (libclamav/pe.c) for ClamAV 0.92 and 0.92.1 allows remote attackers to execute arbitrary code via a crafted Upack PE file.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
ClamAV | =0.92 | |
ClamAV | =0.92.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1100 is classified as high severity due to its potential to allow remote code execution.
To fix CVE-2008-1100, you should upgrade to a later version of ClamAV that is not affected, such as version 0.93 or later.
CVE-2008-1100 affects ClamAV versions 0.92 and 0.92.1.
CVE-2008-1100 is a buffer overflow vulnerability found in the cli_scanpe function of libclamav.
Yes, if exploited, CVE-2008-1100 can allow attackers to execute arbitrary code on the affected systems.