CVE-2008-1387: Medium severity cisco clamav vulnerability
Published Apr 16, 2008
·Updated
ClamAV before 0.93 allows remote attackers to cause a denial of service (CPU consumption) via a crafted ARJ archive, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
Affected Software
8 affected components
Clam Anti-Virus clamav=0.92
Clam Anti-Virus clamav=0.90rc1
Clam Anti-Virus clamav=0.90.1
Clam Anti-Virus clamav=0.91
Clam Anti-Virus clamav=0.90
Clam Anti-Virus clamav=0.90_rc1.1
Clam Anti-Virus clamav=0.90_rc2
Clam Anti-Virus clamav=0.90_rc3
Remediation
Event History
Apr 16, 2008
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1387?
CVE-2008-1387 has a medium severity rating due to its potential to cause denial of service by consuming excessive CPU resources.
2
How do I fix CVE-2008-1387?
To fix CVE-2008-1387, upgrade ClamAV to version 0.93 or later, where the vulnerability has been addressed.
3
What types of files are affected by CVE-2008-1387?
CVE-2008-1387 specifically affects crafted ARJ archive files.
4
Is CVE-2008-1387 easy to exploit?
Yes, CVE-2008-1387 can be easily exploited by sending a specially crafted ARJ archive to a vulnerable version of ClamAV.
5
Which versions of ClamAV are affected by CVE-2008-1387?
CVE-2008-1387 affects ClamAV versions prior to 0.93, including 0.90 through 0.92.