Vulnerability Name: | CVE-2005-1922 (CCN-21206) | ||||||||
Assigned: | 2005-06-29 | ||||||||
Published: | 2005-06-29 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | The MS-Expand file handling in Clam AntiVirus (ClamAV) before 0.86 allows remote attackers to cause a denial of service (file descriptor and memory consumption) via a crafted file that causes repeated errors in the cli_msexpand function. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2005-1922 Source: MITRE Type: CNA CVE-2005-2056 Source: CCN Type: Conectiva Linux Security Announcement CLSA-2005:973 Fixes for two security vulnerabilities in clamav Source: CCN Type: SA15811 ClamAV Quantum Decompressor Denial of Service Vulnerability Source: CONFIRM Type: Patch http://sourceforge.net/project/shownotes.php?release_id=336462 Source: CCN Type: SourceForge.net Project: Clam AntiVirus: Release Notes Source: CCN Type: ClamAV Download Web page clamav 0.86.1 released Source: DEBIAN Type: UNKNOWN DSA-737 Source: DEBIAN Type: DSA-737 clamav -- remote denial of service Source: CCN Type: GLSA-200506-23 Clam AntiVirus: Denial of Service vulnerability Source: CCN Type: iDEFENSE Security Advisory 06.29.05 Clam AntiVirus ClamAV MS-Expand File Handling DoS Vulnerability Source: IDEFENSE Type: Patch, Vendor Advisory 20050629 Clam AntiVirus ClamAV MS-Expand File Handling DoS Vulnerability Source: CCN Type: OSVDB ID: 17646 Clam AntiVirus MS-Expand File Handling DoS Source: CCN Type: BID-14058 Clam Anti-Virus ClamAV Unspecified Quantum Decompressor Denial Of Service Vulnerability Source: CCN Type: BID-14089 Clam Anti-Virus ClamAV Cabinet File Parsing Remote Denial Of Service Vulnerability Source: CCN Type: BID-14090 Clam Anti-Virus ClamAV MS-Expand File Parsing Remote Denial Of Service Vulnerability Source: XF Type: UNKNOWN clam-antivirus-cliscanszdd-dos(21206) Source: SUSE Type: SUSE-SA:2005:038 clamav: multiple security and other bugfixes | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |