Vulnerability Name: | CVE-2005-3303 (CCN-24542) | ||||||||||||||||||||
Assigned: | 2005-11-04 | ||||||||||||||||||||
Published: | 2005-11-04 | ||||||||||||||||||||
Updated: | 2011-03-08 | ||||||||||||||||||||
Summary: | The FSG unpacker (fsg.c) in Clam AntiVirus (ClamAV) 0.80 through 0.87 allows remote attackers to cause "memory corruption" and execute arbitrary code via a crafted FSG 1.33 file. | ||||||||||||||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
References: | Source: BUGTRAQ Type: Patch, Vendor Advisory 20051104 ZDI-05-002: Clam Antivirus Remote Code Execution Source: CCN Type: BugTraq Mailing List, Fri Nov 04 2005 - 11:30:06 CST ZDI-05-002: Clam Antivirus Remote Code Execution Source: MITRE Type: CNA CVE-2005-3303 Source: CCN Type: SA17184 Clam AntiVirus OLE2 Unpacker Potential Denial of Service Source: SECUNIA Type: UNKNOWN 17184 Source: CCN Type: SA17434 Clam AntiVirus CAB/FSG File Handling and base64 MIME Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 17434 Source: SECUNIA Type: UNKNOWN 17448 Source: SECUNIA Type: UNKNOWN 17451 Source: SECUNIA Type: UNKNOWN 17501 Source: SECUNIA Type: UNKNOWN 17559 Source: SREASON Type: UNKNOWN 146 Source: CCN Type: SECTRACK ID: 1015154 Clam AntiVirus CAB, FSG, and OLE Bugs Let Remote Users Deny Service or Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1015154 Source: CCN Type: SourceForge.net: Files Clam AntiVirus - File Release Notes and Changelog - Release Name: 0.87.1 Source: CONFIRM Type: Patch http://sourceforge.net/project/shownotes.php?release_id=368319 Source: DEBIAN Type: UNKNOWN DSA-887 Source: DEBIAN Type: DSA-887 clamav -- several vulnerabilities Source: GENTOO Type: UNKNOWN GLSA-200511-04 Source: MANDRIVA Type: UNKNOWN MDKSA-2005:205 Source: OSVDB Type: UNKNOWN 20482 Source: CCN Type: OSVDB ID: 20482 Clam AntiVirus libclamav/fsg.c FSG File Processing Overflow Source: BID Type: UNKNOWN 15318 Source: CCN Type: BID-15318 Clam Anti-Virus ClamAV FSG File Handling Buffer Overflow Vulnerability Source: VUPEN Type: UNKNOWN ADV-2005-2294 Source: MISC Type: Patch, Vendor Advisory http://www.zerodayinitiative.com/advisories/ZDI-05-002.html Source: XF Type: UNKNOWN clamav-fsg-bo(24542) Source: SUSE Type: SUSE-SR:2005:026 SUSE Security Summary Report | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |