CVE-2008-3912: Null Pointer Dereference
Published Sep 9, 2008
·Updated
libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an out-of-memory condition.
Affected Software
2 affected components
clamav clamav<0.94
Debian Debian Linux=4.0
Remediation
Patch Available
Event History
Sep 9, 2008
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3912?
CVE-2008-3912 is classified as a denial of service vulnerability with potentially severe impact.
2
How do I fix CVE-2008-3912?
To fix CVE-2008-3912, upgrade to version 0.94 or later of ClamAV.
3
Which versions of ClamAV are affected by CVE-2008-3912?
CVE-2008-3912 affects all versions of ClamAV before 0.94.
4
Is CVE-2008-3912 present in Debian 4.0?
Yes, CVE-2008-3912 is present in Debian 4.0 when it includes a vulnerable version of ClamAV.
5
What risk do I face if I do not address CVE-2008-3912?
If not addressed, CVE-2008-3912 can lead to application crashes, causing service interruptions.