CVE-2008-6680: Medium severity clamav vulnerability
Published Apr 8, 2009
·Updated
libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.
Affected Software
4 affected components
clamav clamav=0.93.1
clamav clamav=0.94
clamav clamav<=0.94.2
clamav clamav=0.94.1
Event History
Apr 8, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-6680?
CVE-2008-6680 is considered a high severity vulnerability due to its potential to cause a denial of service through a crash.
2
How do I fix CVE-2008-6680?
To fix CVE-2008-6680, upgrade ClamAV to the latest version that is above 0.95.
3
Which versions of ClamAV are affected by CVE-2008-6680?
CVE-2008-6680 affects ClamAV versions prior to 0.95 including 0.93.1, 0.94, and up to 0.94.2.
4
What type of attack does CVE-2008-6680 facilitate?
CVE-2008-6680 facilitates a remote denial of service attack via a crafted EXE file.
5
Is there a workaround for CVE-2008-6680?
There is no known workaround for CVE-2008-6680; the best mitigation is upgrading the affected software.