Vulnerability Name:

CVE-2008-3912 (CCN-45056)

Assigned:2008-09-03
Published:2008-09-03
Updated:2020-11-09
Summary:libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an out-of-memory condition.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-399
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2008-3912

Source: CONFIRM
Type: Broken Link
http://kolab.org/security/kolab-vendor-notice-22.txt

Source: APPLE
Type: Mailing List, Third Party Advisory
APPLE-SA-2008-10-09

Source: SUSE
Type: Mailing List, Third Party Advisory
SUSE-SR:2008:018

Source: CCN
Type: SA31906
Kolab Server ClamAV Denial of Service

Source: SECUNIA
Type: Third Party Advisory
31906

Source: CCN
Type: SA31929
Astaro update for ClamAV

Source: SECUNIA
Type: Third Party Advisory
31982

Source: SECUNIA
Type: Third Party Advisory
32030

Source: CCN
Type: SA32222
Apple Mac OS X Security Update Fixes Multiple Vulnerabilities

Source: SECUNIA
Type: Third Party Advisory
32222

Source: SECUNIA
Type: Third Party Advisory
32424

Source: SECUNIA
Type: Third Party Advisory
32699

Source: GENTOO
Type: Third Party Advisory
GLSA-200809-18

Source: CCN
Type: SECTRACK ID: 1020828
Clam AntiVirus Memory Access Errors Let Remote Users Deny Service

Source: CONFIRM
Type: Patch, Third Party Advisory
http://sourceforge.net/project/shownotes.php?group_id=86638&release_id=623661

Source: CCN
Type: Apple Web site
About Security Update 2008-007

Source: CONFIRM
Type: Third Party Advisory
http://support.apple.com/kb/HT3216

Source: CONFIRM
Type: Broken Link
http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLog

Source: CCN
Type: Astaro Web site
Up2Date 7.302 Released

Source: CCN
Type: Clam AntiVirus Web site
Clam AntiVirus

Source: DEBIAN
Type: Third Party Advisory
DSA-1660

Source: DEBIAN
Type: DSA-1660
clamav -- null pointer derefence

Source: CCN
Type: GLSA-200809-18
ClamAV: Multiple Denials of Service

Source: MANDRIVA
Type: Third Party Advisory
MDVSA-2008:189

Source: CCN
Type: oss-security Mailing List, Wed, 3 Sep 2008 11:03:27 +0200
request for CVE: clamav 0.94 release

Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-security] 20080903 request for CVE: clamav 0.94 release

Source: CCN
Type: oss-security Mailing List, Thu, 4 Sep 2008 12:44:44 -0400 (EDT)
Re: request for CVE: clamav 0.94 release

Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-security] 20080904 Re: request for CVE: clamav 0.94 release

Source: CCN
Type: OSVDB ID: 48237
ClamAV libclamav Unspecified Memory Exhaustion DoS

Source: BID
Type: Patch, Third Party Advisory, VDB Entry
31051

Source: CCN
Type: BID-31051
ClamAV Multiple Unspecified Memory Corruption Vulnerabilities

Source: BID
Type: Third Party Advisory, VDB Entry
31681

Source: CCN
Type: BID-31681
RETIRED: Apple Mac OS X 2008-007 Multiple Security Vulnerabilities

Source: SECTRACK
Type: Third Party Advisory, VDB Entry
1020828

Source: VUPEN
Type: Permissions Required
ADV-2008-2564

Source: VUPEN
Type: Permissions Required
ADV-2008-2780

Source: XF
Type: Third Party Advisory, VDB Entry
clamav-libclamav-dos(45056)

Source: XF
Type: UNKNOWN
clamav-libclamav-dos(45056)

Source: FEDORA
Type: Third Party Advisory
FEDORA-2008-9644

Source: FEDORA
Type: Third Party Advisory
FEDORA-2008-9651

Source: SUSE
Type: SUSE-SR:2008:018
SUSE Security Summary Report

Source: MISC
Type: Broken Link
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1141

Vulnerable Configuration:Configuration 1:
  • cpe:/a:clamav:clamav:*:*:*:*:*:*:*:* (Version < 0.94)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:clamav:clamav:0.65:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.83:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.87:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.84:rc2:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.91.2:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.92:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.91.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.92.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90:rc1.1:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90:rc2:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90:rc3:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90:rc1:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.91:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.15:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.20:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.21:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.22:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.23:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.24:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.51:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.52:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.53:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.54:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.60:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.60p:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.67:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.68:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.68.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.70:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.71:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.72:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.73:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.74:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.75:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.75.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.80:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.80:rc1:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.80:rc2:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.80:rc3:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.80:rc4:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.81:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.81:rc1:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.82:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.84:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.84:rc1:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.85:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.85.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.86:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.86:rc1:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.86.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.86.2:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.87.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.88:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.88.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.88.3:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.88.4:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.88.5:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.88.6:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.88.7:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.88.2:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90.3:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.91.2_p0:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.92_p0:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.93:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90.3_p1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90.3_p0:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90.2_p0:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90.1_p0:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.88.7_p0:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.88.7_p1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.12:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.13:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.14:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.14:pre:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.80:rc:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.93.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.93.3:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.91:rc2:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.91:rc1:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.93.2:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.02:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.03:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.05:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.01:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.10:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90.2:*:*:*:*:*:*:*
  • AND
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007.1:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.0::x86-64:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.1:x86_64:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007.1::x86-64:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.1:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5.5:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20083912
    V
    CVE-2008-3912
    2017-09-27
    oval:org.mitre.oval:def:7878
    P
    DSA-1660 clamav -- null pointer dereference, resource exhaustion
    2014-06-23
    oval:org.mitre.oval:def:17755
    P
    DSA-1660-1 clamav - denial of service
    2014-06-23
    oval:org.debian:def:1660
    V
    null pointer dereference, resource exhaustion
    2008-10-26
    BACK
    clamav clamav *
    debian debian linux 4.0
    clamav clamav 0.65
    clamav clamav 0.83
    clamav clamav 0.87
    clamav clamav 0.84 rc2
    clamav clamav 0.91.2
    clamav clamav 0.92
    clamav clamav 0.91.1
    clamav clamav 0.92.1
    clamav clamav 0.90
    clamav clamav 0.90 rc1.1
    clamav clamav 0.90 rc2
    clamav clamav 0.90 rc3
    clamav clamav 0.90.1
    clamav clamav 0.90 rc1
    clamav clamav 0.91
    clamav clamav 0.15
    clamav clamav 0.20
    clamav clamav 0.21
    clamav clamav 0.22
    clamav clamav 0.23
    clamav clamav 0.24
    clamav clamav 0.51
    clamav clamav 0.52
    clamav clamav 0.53
    clamav clamav 0.54
    clamav clamav 0.60
    clamav clamav 0.60p
    clamav clamav 0.67
    clamav clamav 0.68
    clamav clamav 0.68.1
    clamav clamav 0.70
    clamav clamav 0.71
    clamav clamav 0.72
    clamav clamav 0.73
    clamav clamav 0.74
    clamav clamav 0.75
    clamav clamav 0.75.1
    clamav clamav 0.80
    clamav clamav 0.80 rc1
    clamav clamav 0.80 rc2
    clamav clamav 0.80 rc3
    clamav clamav 0.80 rc4
    clamav clamav 0.81
    clamav clamav 0.81 rc1
    clamav clamav 0.82
    clamav clamav 0.84
    clamav clamav 0.84 rc1
    clamav clamav 0.85
    clamav clamav 0.85.1
    clamav clamav 0.86
    clamav clamav 0.86 rc1
    clamav clamav 0.86.1
    clamav clamav 0.86.2
    clamav clamav 0.87.1
    clamav clamav 0.88
    clamav clamav 0.88.1
    clamav clamav 0.88.3
    clamav clamav 0.88.4
    clamav clamav 0.88.5
    clamav clamav 0.88.6
    clamav clamav 0.88.7
    clamav clamav 0.88.2
    clamav clamav 0.90.3
    clamav clamav 0.91.2_p0
    clamav clamav 0.92_p0
    clamav clamav 0.93
    clamav clamav 0.90.3_p1
    clamav clamav 0.90.3_p0
    clamav clamav 0.90.2_p0
    clamav clamav 0.90.1_p0
    clamav clamav 0.88.7_p0
    clamav clamav 0.88.7_p1
    clamav clamav 0.12
    clamav clamav 0.13
    clamav clamav 0.14
    clamav clamav 0.14 pre
    clamav clamav 0.80 rc
    clamav clamav 0.93.1
    clamav clamav 0.93.3
    clamav clamav 0.91 rc2
    clamav clamav 0.91 rc1
    clamav clamav 0.93.2
    clamav clamav 0.02
    clamav clamav 0.03
    clamav clamav 0.05
    clamav clamav 0.01
    clamav clamav 0.10
    clamav clamav 0.90.2
    gentoo linux *
    mandrakesoft mandrake linux corporate server 3.0
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 3.0
    mandrakesoft mandrake linux 2007.1
    mandrakesoft mandrake linux 2008.0
    debian debian linux 4.0
    mandrakesoft mandrake linux 2008.0
    mandrakesoft mandrake linux 2008.1 x86_64
    mandrakesoft mandrake linux 2007.1
    apple mac os x server 10.4.11
    mandrakesoft mandrake linux 2008.1
    apple mac os x server 10.5.5