CVE-2008-3215: Medium severity cisco clamav vulnerability
Published Jul 18, 2008
·Updated
libclamav/petite.c in ClamAV before 0.93.3 allows remote attackers to cause a denial of service via a malformed Petite file that triggers an out-of-bounds memory access. NOTE: this issue exists because of an incomplete fix for CVE-2008-2713.
Affected Software
19 affected components
Clam Anti-Virus clamav=0.90.2-p0
Clam Anti-Virus clamav=0.91.2-p0
Clam Anti-Virus clamav=0.90.1
Clam Anti-Virus clamav=0.90
Clam Anti-Virus clamav=0.90.3-p0
Clam Anti-Virus clamav=0.88.7
Clam Anti-Virus clamav=0.88.7-p0
Clam Anti-Virus clamav=0.93
Clam Anti-Virus clamav=0.90.2
Clam Anti-Virus clamav=0.90.1-p0
Clam Anti-Virus clamav=0.88.2
Clam Anti-Virus clamav=0.90.3
Clam Anti-Virus clamav=0.88.6
Clam Anti-Virus clamav=0.90.3-p1
Clam Anti-Virus clamav=0.88.5
Clam Anti-Virus clamav=0.92.1
Clam Anti-Virus clamav=0.92-p0
Clam Anti-Virus clamav=0.88.7-p1
Clam Anti-Virus clamav=0.88.4
Event History
Jul 18, 2008
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3215?
CVE-2008-3215 is considered a denial-of-service vulnerability due to out-of-bounds memory access.
2
How do I fix CVE-2008-3215?
To fix CVE-2008-3215, upgrade ClamAV to version 0.93.3 or later.
3
What versions of ClamAV are affected by CVE-2008-3215?
CVE-2008-3215 affects ClamAV versions prior to 0.93.3, including 0.88.2 through 0.93.
4
What type of attack does CVE-2008-3215 enable?
CVE-2008-3215 enables remote attackers to cause a denial of service by exploiting malformed Petite files.
5
Is there a mitigation for CVE-2008-3215 if immediate upgrade is not possible?
There is no known mitigation for CVE-2008-3215 other than upgrading to a secure version.