CVE-2011-2721: Medium severity clamav vulnerability
An off-by-one error was found in the way the hash manager of Clam AntiVirus, a GPL anti-virus toolkit for UNIX, performed scan of messages with certain hashes. A remote attacker could provide a message with specially-crafted hash signature in it, leading to denial of service (clamscan executable crash).
Upstream bug report: [1] https://wwws.clamav.net/bugzilla/showbug.cgi?id=2818
Relevant patch: [2] http://git.clamav.net/gitweb?p=clamav-devel.git;a=commit;h=4842733eb3f09be61caeed83778bb6679141dbc5
Other references: [3] https://bugzilla.novell.com/showbug.cgi?id=708263 [4] http://git.clamav.net/gitweb?p=clamav-devel.git;a=blobplain;f=ChangeLog;hb=clamav-0.97.2 [5] http://www.clamav.net/lang/en/
Other sources
Off-by-one error in the clihmscan function in matcher-hash.c in libclamav in ClamAV before 0.97.2 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message that is not properly handled during certain hash calculations.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2721?
CVE-2011-2721 is classified as a denial-of-service vulnerability with medium severity.
How can I fix CVE-2011-2721?
To fix CVE-2011-2721, upgrade Clam AntiVirus to a version later than 0.97.1 that addresses this vulnerability.
What versions of ClamAV are affected by CVE-2011-2721?
CVE-2011-2721 affects multiple versions of Clam AntiVirus including 0.95.2, 0.86.2, and other versions up to 0.97.1.
What kind of attacks can be carried out using CVE-2011-2721?
An attacker can use CVE-2011-2721 to exploit an off-by-one error to create specially-crafted hash signatures that cause a denial of service.
Is there a workaround for CVE-2011-2721?
While upgrading is the best solution, temporarily restricting access to the affected ClamAV services can serve as a workaround.