CVE-2010-1311: Input Validation
The qtmdecompress function in libclamav/mspack.c in ClamAV before 0.96 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted CAB archive that uses the Quantum (aka .Q) compression format. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1311?
CVE-2010-1311 has been classified as a Medium severity vulnerability that can lead to denial of service.
How do I fix CVE-2010-1311?
To fix CVE-2010-1311, upgrade to ClamAV version 0.96 or later.
What impact does CVE-2010-1311 have on affected systems?
The impact of CVE-2010-1311 includes memory corruption and potential application crashes when processing crafted CAB archives.
What versions of ClamAV are affected by CVE-2010-1311?
CVE-2010-1311 affects ClamAV versions before 0.96, including versions like 0.95.2 and earlier.
Is there a workaround for CVE-2010-1311?
There is no specific workaround for CVE-2010-1311; upgrading to a patched version is the recommended approach.