CVE-2011-1003: Double Free
Double free vulnerability in the vbareadprojectstrings function in vbaextract.c in libclamav in ClamAV before 0.97 might allow remote attackers to execute arbitrary code via crafted Visual Basic for Applications (VBA) data in a Microsoft Office document. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1003?
CVE-2011-1003 is categorized as a critical vulnerability that could allow remote attackers to execute arbitrary code.
How do I fix CVE-2011-1003?
To remediate CVE-2011-1003, you should upgrade to ClamAV versions later than 0.97 which contain patches for this vulnerability.
Which versions of ClamAV are affected by CVE-2011-1003?
CVE-2011-1003 affects ClamAV versions prior to 0.97, including versions such as 0.96.5 and earlier.
What kind of attack can exploit CVE-2011-1003?
CVE-2011-1003 can be exploited by attackers who send malicious Visual Basic for Applications (VBA) data within Microsoft Office documents.
Is user intervention required for CVE-2011-1003 exploitation to succeed?
Yes, successful exploitation of CVE-2011-1003 typically requires the user to open a compromised Microsoft Office document.