First published: Thu Nov 13 2008(Updated: )
Off-by-one error in the get_unicode_name function (libclamav/vba_extract.c) in Clam Anti-Virus (ClamAV) before 0.94.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted VBA project file, which triggers a heap-based buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Clam Anti-virus Clamav | =0.84-rc2 | |
Clam Anti-virus Clamav | =0.86-rc1 | |
Clam Anti-virus Clamav | =0.24 | |
Clam Anti-virus Clamav | =0.90.2-p0 | |
Clam Anti-virus Clamav | =0.20 | |
Clam Anti-virus Clamav | =0.91.2-p0 | |
Clam Anti-virus Clamav | =0.03 | |
Clam Anti-virus Clamav | =0.84 | |
Clam Anti-virus Clamav | =0.92 | |
Clam Anti-virus Clamav | =0.90rc1 | |
Clam Anti-virus Clamav | =0.91.2 | |
Clam Anti-virus Clamav | =0.80 | |
Clam Anti-virus Clamav | =0.90.1 | |
Clam Anti-virus Clamav | =0.84_rc1 | |
Clam Anti-virus Clamav | =0.01 | |
Clam Anti-virus Clamav | =0.91 | |
Clam Anti-virus Clamav | =0.15 | |
Clam Anti-virus Clamav | =0.90 | |
Clam Anti-virus Clamav | =0.93.2 | |
Clam Anti-virus Clamav | =0.06 | |
Clam Anti-virus Clamav | =0.80_rc3 | |
Clam Anti-virus Clamav | =0.14 | |
Clam Anti-virus Clamav | =0.02 | |
Clam Anti-virus Clamav | =0.04 | |
Clam Anti-virus Clamav | =0.80_rc4 | |
Clam Anti-virus Clamav | =0.65 | |
Clam Anti-virus Clamav | =0.10 | |
Clam Anti-virus Clamav | =0.75 | |
Clam Anti-virus Clamav | =0.68 | |
Clam Anti-virus Clamav | =0.80-rc | |
Clam Anti-virus Clamav | =0.90.3-p0 | |
Clam Anti-virus Clamav | =0.71 | |
Clam Anti-virus Clamav | =0.80-rc4 | |
Clam Anti-virus Clamav | =0.88.3 | |
Clam Anti-virus Clamav | =0.88.7 | |
Clam Anti-virus Clamav | =0.86.1 | |
Clam Anti-virus Clamav | =0.82 | |
Clam Anti-virus Clamav | =0.88.1 | |
Clam Anti-virus Clamav | =0.91.1 | |
Clam Anti-virus Clamav | =0.73 | |
Clam Anti-virus Clamav | =0.88.7-p0 | |
Clam Anti-virus Clamav | =0.72 | |
Clam Anti-virus Clamav | =0.85.1 | |
Clam Anti-virus Clamav | =0.84-rc1 | |
Clam Anti-virus Clamav | =0.87 | |
Clam Anti-virus Clamav | =0.93.3 | |
Clam Anti-virus Clamav | =0.86_rc1 | |
Clam Anti-virus Clamav | =0.85 | |
Clam Anti-virus Clamav | =0.93 | |
Clam Anti-virus Clamav | =0.12 | |
Clam Anti-virus Clamav | =0.80_rc1 | |
Clam Anti-virus Clamav | =0.74 | |
Clam Anti-virus Clamav | =0.75.1 | |
Clam Anti-virus Clamav | =0.86.2 | |
Clam Anti-virus Clamav | =0.67 | |
Clam Anti-virus Clamav | =0.81 | |
Clam Anti-virus Clamav | =0.90.2 | |
Clam Anti-virus Clamav | =0.21 | |
Clam Anti-virus Clamav | =0.11 | |
Clam Anti-virus Clamav | =0.81_rc1 | |
Clam Anti-virus Clamav | =0.54 | |
Clam Anti-virus Clamav | =0.90.1-p0 | |
Clam Anti-virus Clamav | =0.88.2 | |
Clam Anti-virus Clamav | =0.90.3 | |
Clam Anti-virus Clamav | =0.88.6 | |
Clam Anti-virus Clamav | =0.53 | |
Clam Anti-virus Clamav | =0.70 | |
Clam Anti-virus Clamav | =0.90.3-p1 | |
Clam Anti-virus Clamav | =0.90_rc1.1 | |
Clam Anti-virus Clamav | =0.60p | |
Clam Anti-virus Clamav | =0.90_rc2 | |
Clam Anti-virus Clamav | =0.90_rc3 | |
Clam Anti-virus Clamav | <=0.94 | |
Clam Anti-virus Clamav | =0.91rc2 | |
Clam Anti-virus Clamav | =0.13 | |
Clam Anti-virus Clamav | =0.81-rc1 | |
Clam Anti-virus Clamav | =0.80_rc2 | |
Clam Anti-virus Clamav | =0.88.5 | |
Clam Anti-virus Clamav | =0.92.1 | |
Clam Anti-virus Clamav | =0.60 | |
Clam Anti-virus Clamav | =0.14-pre | |
Clam Anti-virus Clamav | =0.86 | |
Clam Anti-virus Clamav | =0.91rc1 | |
Clam Anti-virus Clamav | =0.83 | |
Clam Anti-virus Clamav | =0.92-p0 | |
Clam Anti-virus Clamav | =0.05 | |
Clam Anti-virus Clamav | =0.68.1 | |
Clam Anti-virus Clamav | =0.88 | |
Clam Anti-virus Clamav | =0.80-rc3 | |
Clam Anti-virus Clamav | =0.87.1 | |
Clam Anti-virus Clamav | =0.88.7-p1 | |
Clam Anti-virus Clamav | =0.88.4 | |
Clam Anti-virus Clamav | =0.93.1 | |
Clam Anti-virus Clamav | =0.84_rc2 | |
Clam Anti-virus Clamav | =0.51 | |
Clam Anti-virus Clamav | =0.80-rc2 | |
Clam Anti-virus Clamav | =0.23 | |
Clam Anti-virus Clamav | =0.52 | |
Clam Anti-virus Clamav | =0.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.