Vulnerability Name:

CVE-2007-3725 (CCN-35367)

Assigned:2007-07-11
Published:2007-07-11
Updated:2018-10-15
Summary:The RAR VM (unrarvm.c) in Clam Antivirus (ClamAV) before 0.91 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive, resulting in a NULL pointer dereference.
CVSS v3 Severity:3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Denial of Service
References:Source: CCN
Type: Full-Disclosure Mailing List, Wed Jul 11 2007 - 10:46:56 CDT
Advisory - Clam AntiVirus RAR File Handling Denial Of Service Vulnerability.

Source: CCN
Type: Full-Disclosure Mailing List, Wed Jul 11 2007 - 10:32:53 CDT
Re: Advisory - Clam AntiVirus RAR File Handling Denial Of Service Vulnerability

Source: MITRE
Type: CNA
CVE-2007-3725

Source: CCN
Type: Apple Web site
About Security Update 2008-002

Source: CONFIRM
Type: UNKNOWN
http://docs.info.apple.com/article.html?artnum=307562

Source: CCN
Type: Kolab Security Issue 16 20070724
Kolab Server, ClamAV denial of service

Source: CONFIRM
Type: UNKNOWN
http://kolab.org/security/kolab-vendor-notice-16.txt

Source: APPLE
Type: UNKNOWN
APPLE-SA-2008-03-18

Source: FULLDISC
Type: UNKNOWN
20070711 Advisory - Clam AntiVirus RAR File Handling Denial Of Service Vulnerability.

Source: OSVDB
Type: UNKNOWN
36907

Source: CCN
Type: SA26038
ClamAV RAR Archive Processing Denial of Service Vulnerability

Source: SECUNIA
Type: UNKNOWN
26038

Source: SECUNIA
Type: UNKNOWN
26164

Source: CCN
Type: SA26209
Kolab Server ClamAV RAR Archive Processing Denial of Service Vulnerability

Source: SECUNIA
Type: UNKNOWN
26209

Source: SECUNIA
Type: UNKNOWN
26226

Source: SECUNIA
Type: UNKNOWN
26231

Source: SECUNIA
Type: UNKNOWN
26377

Source: CCN
Type: SA29420
Mac OS X Security Update Fixes Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
29420

Source: GENTOO
Type: UNKNOWN
GLSA-200708-04

Source: DEBIAN
Type: UNKNOWN
DSA-1340

Source: DEBIAN
Type: DSA-1340
clamav -- null pointer dereference

Source: CCN
Type: GLSA-200708-04
ClamAV: Denial of Service

Source: MANDRIVA
Type: UNKNOWN
MDKSA-2007:150

Source: CCN
Type: Metaeye Security Group Advisory 54
Clam AntiVirus RAR File Handling Denial Of Service Vulnerability

Source: MISC
Type: Exploit, Patch, Vendor Advisory
http://www.metaeye.org/advisories/54

Source: SUSE
Type: UNKNOWN
SUSE-SR:2007:015

Source: CCN
Type: OSVDB ID: 36907
Clam AntiVirus RAR Archive Processing DoS

Source: BUGTRAQ
Type: UNKNOWN
20070711 Advisory - Clam AntiVirus RAR File Handling Denial Of Service Vulnerability.

Source: CCN
Type: BID-24866
Multiple Vendors RAR Handling Remote Null Pointer Dereference Vulnerability

Source: TRUSTIX
Type: UNKNOWN
2007-0023

Source: VUPEN
Type: UNKNOWN
ADV-2007-2509

Source: VUPEN
Type: UNKNOWN
ADV-2007-2643

Source: VUPEN
Type: UNKNOWN
ADV-2008-0924

Source: XF
Type: UNKNOWN
clamav-rarvm-dos(35367)

Source: XF
Type: UNKNOWN
clamav-rarvm-dos(35367)

Source: SUSE
Type: SUSE-SR:2007:015
SUSE Security Summary Report

Source: CCN
Type: ClamAV Bugzilla Bug 555
RAR Files Handling Denial of Service vulnerability

Source: CONFIRM
Type: UNKNOWN
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=555

Vulnerable Configuration:Configuration 1:
  • cpe:/a:clam_anti-virus:clamav:0.15:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.20:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.21:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.22:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.23:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.24:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.51:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.52:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.53:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.54:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.60:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.60p:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.65:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.67:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.68:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.68.1:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.70:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.71:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.72:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.73:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.74:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.75:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.75.1:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.80:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.80_rc1:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.80_rc2:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.80_rc3:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.80_rc4:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.81:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.81_rc1:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.82:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.83:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.84:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.84_rc1:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.84_rc2:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.85:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.85.1:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.86:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.86.1:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.86.2:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.86_rc1:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.87:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.87.1:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.88:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.88.1:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.88.3:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.88.4:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.88.5:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.88.6:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.88.7:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.90:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.90_rc1.1:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.90_rc2:*:*:*:*:*:*:*
  • OR cpe:/a:clam_anti-virus:clamav:0.90_rc3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20073725
    V
    CVE-2007-3725
    2015-11-16
    oval:org.mitre.oval:def:18711
    P
    DSA-1340-1 clamav - null pointer dereference
    2014-06-23
    oval:org.debian:def:1340
    V
    null pointer dereference
    2007-07-24
    BACK
    clam_anti-virus clamav 0.15
    clam_anti-virus clamav 0.20
    clam_anti-virus clamav 0.21
    clam_anti-virus clamav 0.22
    clam_anti-virus clamav 0.23
    clam_anti-virus clamav 0.24
    clam_anti-virus clamav 0.51
    clam_anti-virus clamav 0.52
    clam_anti-virus clamav 0.53
    clam_anti-virus clamav 0.54
    clam_anti-virus clamav 0.60
    clam_anti-virus clamav 0.60p
    clam_anti-virus clamav 0.65
    clam_anti-virus clamav 0.67
    clam_anti-virus clamav 0.68
    clam_anti-virus clamav 0.68.1
    clam_anti-virus clamav 0.70
    clam_anti-virus clamav 0.71
    clam_anti-virus clamav 0.72
    clam_anti-virus clamav 0.73
    clam_anti-virus clamav 0.74
    clam_anti-virus clamav 0.75
    clam_anti-virus clamav 0.75.1
    clam_anti-virus clamav 0.80
    clam_anti-virus clamav 0.80_rc1
    clam_anti-virus clamav 0.80_rc2
    clam_anti-virus clamav 0.80_rc3
    clam_anti-virus clamav 0.80_rc4
    clam_anti-virus clamav 0.81
    clam_anti-virus clamav 0.81_rc1
    clam_anti-virus clamav 0.82
    clam_anti-virus clamav 0.83
    clam_anti-virus clamav 0.84
    clam_anti-virus clamav 0.84_rc1
    clam_anti-virus clamav 0.84_rc2
    clam_anti-virus clamav 0.85
    clam_anti-virus clamav 0.85.1
    clam_anti-virus clamav 0.86
    clam_anti-virus clamav 0.86.1
    clam_anti-virus clamav 0.86.2
    clam_anti-virus clamav 0.86_rc1
    clam_anti-virus clamav 0.87
    clam_anti-virus clamav 0.87.1
    clam_anti-virus clamav 0.88
    clam_anti-virus clamav 0.88.1
    clam_anti-virus clamav 0.88.3
    clam_anti-virus clamav 0.88.4
    clam_anti-virus clamav 0.88.5
    clam_anti-virus clamav 0.88.6
    clam_anti-virus clamav 0.88.7
    clam_anti-virus clamav 0.90
    clam_anti-virus clamav 0.90_rc1.1
    clam_anti-virus clamav 0.90_rc2
    clam_anti-virus clamav 0.90_rc3