First published: Fri Nov 15 2019(Updated: )
ClamAV before 0.97.7 has WWPack corrupt heap memory
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Clamav Clamav | <0.97.7 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =17 | |
Fedoraproject Fedora | =18 | |
debian/clamav | 0.103.10+dfsg-0+deb11u1 1.0.5+dfsg-1~deb12u1 1.3.1+dfsg-4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-7087 is a vulnerability in ClamAV before 0.97.7 that allows attackers to corrupt heap memory.
CVE-2013-7087 has a severity rating of 9.8 (Critical).
CVE-2013-7087 affects ClamAV versions before 0.97.7.
To fix CVE-2013-7087, update ClamAV to version 0.97.7 or later.
You can find more information about CVE-2013-7087 on the following references: [link1](https://github.com/vrtadmin/clamav-devel/commit/71990820d01c246e4e61408a3659dd9d92949b38), [link2](https://github.com/vrtadmin/clamav-devel/commits/master/libclamav/wwunpack.c), [link3](https://security-tracker.debian.org/tracker/CVE-2013-7087).