Vulnerability Name: | CVE-2005-2450 (CCN-21555) | ||||||||
Assigned: | 2005-07-25 | ||||||||
Published: | 2005-07-25 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Multiple integer overflows in the (1) TNEF, (2) CHM, or (3) FSG file format processors in libclamav for Clam AntiVirus (ClamAV) 0.86.1 and earlier allow remote attackers to gain privileges via a crafted e-mail message. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Jul 25 2005 - 08:29:28 CDT ClamAV Multiple Rem0te Buffer Overflows Source: MITRE Type: CNA CVE-2005-2450 Source: CONECTIVA Type: UNKNOWN CLSA-2005:987 Source: CCN Type: Conectiva Linux Security Announcement CLSA-2005:987 clamav -- Integer overflow vulnerabilities Source: BUGTRAQ Type: UNKNOWN 20050725 ClamAV Multiple Rem0te Buffer Overflows Source: CCN Type: SA16180 Clam AntiVirus Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 16180 Source: SECUNIA Type: UNKNOWN 16229 Source: SECUNIA Type: UNKNOWN 16250 Source: SECUNIA Type: UNKNOWN 16296 Source: SECUNIA Type: UNKNOWN 16458 Source: GENTOO Type: UNKNOWN GLSA-200507-25 Source: CONFIRM Type: Patch http://sourceforge.net/project/shownotes.php?release_id=344514 Source: CCN Type: CIAC Information Bulletin P-278 clamav -- integer overflows Source: CCN Type: ClamAV Web site ClamAV: Project News Source: DEBIAN Type: DSA-776 clamav -- integer overflows Source: CCN Type: GLSA-200507-25 Clam AntiVirus: Integer overflows Source: SUSE Type: UNKNOWN SUSE-SR:2005:018 Source: OSVDB Type: UNKNOWN 18257 Source: OSVDB Type: UNKNOWN 18258 Source: OSVDB Type: UNKNOWN 18259 Source: CCN Type: OSVDB ID: 18257 Clam AntiVirus TNEF File Processing Multiple Overflows Source: CCN Type: OSVDB ID: 18258 Clam AntiVirus CHM File Processing Filename Overflow Source: CCN Type: OSVDB ID: 18259 Clam AntiVirus FSG File Processing Overflow Source: BID Type: UNKNOWN 14359 Source: CCN Type: BID-14359 ClamAV Multiple Integer Overflow Vulnerabilities Source: XF Type: UNKNOWN clam-antivirus-file-format-gain-access(21555) Source: XF Type: UNKNOWN clam-antivirus-file-format-gain-access(21555) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |