First published: Fri Nov 15 2019(Updated: )
ClamAV before 0.97.7: dbg_printhex possible information leak
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/clamav | 0.103.10+dfsg-0+deb11u1 1.0.5+dfsg-1~deb12u1 1.3.1+dfsg-4 | |
ClamAV | <0.97.7 | |
Debian | =8.0 | |
Debian | =9.0 | |
Debian | =10.0 | |
Fedora | =17 | |
Fedora | =18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-7089 refers to a vulnerability in ClamAV before version 0.97.7 that can lead to a possible information leak.
CVE-2013-7089 can allow an attacker to leak sensitive information through the dbg_printhex function in ClamAV.
CVE-2013-7089 has a severity level of 7.5 (High).
To fix the CVE-2013-7089 vulnerability, it is recommended to update ClamAV to version 0.97.7 or later.
You can find more information about CVE-2013-7089 on the following websites: [Bugzilla](https://bugzilla.clamav.net/show_bug.cgi?id=6804), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2013-7089), [Gentoo GLSA](http://security.gentoo.org/glsa/glsa-201405-08.xml).