CVE-2011-3627: Medium severity clamav vulnerability
A denial of service flaw was found in the way the bytecode engine of the Clam Antivirus scanner handled recursion level when scanning an unpacked file. If a local user was tricked into scanning a file or directory with 'load bytecode from the database' feature enabled, it could lead to clamscan executable crash.
References: [1] https://bugs.gentoo.org/showbug.cgi?id=387521 [2] http://www.openwall.com/lists/oss-security/2011/10/18/1 [3] http://git.clamav.net/gitweb?p=clamav-devel.git;a=blobplain;f=ChangeLog;hb=clamav-0.97.3
Upstream patch: [4] http://git.clamav.net/gitweb?p=clamav-devel.git;a=commit;h=3d664817f6ef833a17414a4ecea42004c35cc42f
Other sources
The bytecode engine in ClamAV before 0.97.3 allows remote attackers to cause a denial of service (crash) via vectors related to "recursion level" and (1) libclamav/bytecode.c and (2) libclamav/bytecodeapi.c.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3627?
CVE-2011-3627 has been assigned a severity rating that indicates it is a denial of service vulnerability affecting Clam Antivirus.
How do I fix CVE-2011-3627?
To fix CVE-2011-3627, you should upgrade to the latest version of Clam Antivirus that addresses this vulnerability.
What versions of Clam Antivirus are affected by CVE-2011-3627?
CVE-2011-3627 affects multiple versions of Clam Antivirus, including 0.90 to 0.97.2.
Can CVE-2011-3627 be exploited remotely?
CVE-2011-3627 requires local user interaction to exploit, as it involves scanning a file with specific features enabled.
What are the potential impacts of CVE-2011-3627?
The potential impact of CVE-2011-3627 is denial of service, which could cause the Clam Antivirus scanner to crash.