Vulnerability Name: CVE-2008-3914 (CCN-45058) Assigned: 2008-09-03 Published: 2008-09-03 Updated: 2020-11-05 Summary: Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c. CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): LowAvailibility (A): None
CVSS v2 Severity: 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C )7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N )3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
Vulnerability Type: CWE-noinfo CWE-200 Vulnerability Consequences: Other References: Source: MITRE Type: CNACVE-2008-3914 Source: CONFIRM Type: Third Party Advisoryhttp://kolab.org/security/kolab-vendor-notice-22.txt Source: APPLE Type: Mailing List, Third Party AdvisoryAPPLE-SA-2008-10-09 Source: SUSE Type: Mailing List, Third Party AdvisorySUSE-SR:2008:018 Source: CCN Type: SA31906Kolab Server ClamAV Denial of Service Source: SECUNIA Type: Third Party Advisory31906 Source: CCN Type: SA31929Astaro update for ClamAV Source: SECUNIA Type: Third Party Advisory31982 Source: SECUNIA Type: Third Party Advisory32030 Source: CCN Type: SA32222Apple Mac OS X Security Update Fixes Multiple Vulnerabilities Source: SECUNIA Type: Third Party Advisory32222 Source: SECUNIA Type: Third Party Advisory32424 Source: SECUNIA Type: Third Party Advisory32699 Source: GENTOO Type: Third Party AdvisoryGLSA-200809-18 Source: CCN Type: SECTRACK ID: 1020828Clam AntiVirus Memory Access Errors Let Remote Users Deny Service Source: CONFIRM Type: Patch, Third Party Advisoryhttp://sourceforge.net/project/shownotes.php?group_id=86638&release_id=623661 Source: CCN Type: Apple Web siteAbout Security Update 2008-007 Source: CONFIRM Type: Third Party Advisoryhttp://support.apple.com/kb/HT3216 Source: CONFIRM Type: Vendor Advisoryhttp://svn.clamav.net/svn/clamav-devel/trunk/ChangeLog Source: CCN Type: Astaro Web siteUp2Date 7.302 Released Source: CCN Type: Clam AntiVirus Web siteClam AntiVirus Source: DEBIAN Type: Third Party AdvisoryDSA-1660 Source: DEBIAN Type: DSA-1660clamav -- null pointer derefence Source: CCN Type: GLSA-200809-18ClamAV: Multiple Denials of Service Source: MANDRIVA Type: Third Party AdvisoryMDVSA-2008:189 Source: CCN Type: oss-security Mailing List, Wed, 3 Sep 2008 11:03:27 +0200 request for CVE: clamav 0.94 release Source: MLIST Type: Mailing List, Third Party Advisory[oss-security] 20080903 request for CVE: clamav 0.94 release Source: CCN Type: oss-security Mailing List, Thu, 4 Sep 2008 12:44:44 -0400 (EDT) Re: request for CVE: clamav 0.94 release Source: MLIST Type: Mailing List[oss-security] 20080904 Re: request for CVE: clamav 0.94 release Source: CCN Type: OSVDB ID: 48239ClamAV error path File Descriptor Leak Multiple Unspecified Issue Source: BID Type: Patch, Third Party Advisory, VDB Entry31051 Source: CCN Type: BID-31051ClamAV Multiple Unspecified Memory Corruption Vulnerabilities Source: BID Type: Third Party Advisory, VDB Entry31681 Source: CCN Type: BID-31681RETIRED: Apple Mac OS X 2008-007 Multiple Security Vulnerabilities Source: SECTRACK Type: Third Party Advisory, VDB Entry1020828 Source: VUPEN Type: Permissions RequiredADV-2008-2564 Source: VUPEN Type: Permissions RequiredADV-2008-2780 Source: XF Type: Third Party Advisory, VDB Entryclamav-multiple-unspecified(45058) Source: XF Type: UNKNOWNclamav-multiple-unspecified(45058) Source: FEDORA Type: Third Party AdvisoryFEDORA-2008-9644 Source: FEDORA Type: Third Party AdvisoryFEDORA-2008-9651 Source: SUSE Type: SUSE-SR:2008:018SUSE Security Summary Report Source: MISC Type: Issue Trackinghttps://wwws.clamav.net/bugzilla/show_bug.cgi?id=1141 Vulnerable Configuration: Configuration 1 :cpe:/a:clamav:clamav:*:*:*:*:*:*:*:* (Version <= 0.93.3)Configuration CCN 1 :cpe:/a:clamav:clamav:0.65:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.83:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.87:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.84:rc2:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.91.2:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.92:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.91.1:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.92.1:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.90:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.90:rc1.1:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.90:rc2:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.90:rc3:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.90.1:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.90:rc1:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.91:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.15:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.20:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.21:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.22:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.23:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.24:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.51:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.52:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.53:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.54:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.60:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.60p:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.67:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.68:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.68.1:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.70:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.71:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.72:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.73:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.74:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.75:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.75.1:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.80:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.80:rc1:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.80:rc2:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.80:rc3:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.80:rc4:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.81:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.81:rc1:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.82:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.84:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.84:rc1:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.85:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.85.1:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.86:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.86.1:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.86.2:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.87.1:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.88:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.88.1:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.88.3:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.88.4:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.88.5:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.88.6:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.88.7:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.88.2:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.90.3:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.91.2_p0:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.92_p0:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.93:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.90.3_p1:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.90.3_p0:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.90.2_p0:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.90.1_p0:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.88.7_p0:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.88.7_p1:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.12:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.13:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.14:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.14:pre:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.80:rc:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.93.1:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.93.3:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.91:rc2:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.91:rc1:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.93.2:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.02:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.03:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.05:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.01:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.10:*:*:*:*:*:*:* OR cpe:/a:clamav:clamav:0.90.2:*:*:*:*:*:*:* AND cpe:/o:gentoo:linux:*:*:*:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:*:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0::x86_64:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2007.1:*:*:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2008.0::x86-64:*:*:*:*:* OR cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2008.0:*:*:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2008.1:x86_64:*:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2007.1::x86-64:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:* OR cpe:/o:mandrakesoft:mandrake_linux:2008.1:*:*:*:*:*:*:* OR cpe:/o:apple:mac_os_x_server:10.5.5:*:*:*:*:*:*:* Denotes that component is vulnerable Oval Definitions BACK
clamav clamav *
clamav clamav 0.65
clamav clamav 0.83
clamav clamav 0.87
clamav clamav 0.84 rc2
clamav clamav 0.91.2
clamav clamav 0.92
clamav clamav 0.91.1
clamav clamav 0.92.1
clamav clamav 0.90
clamav clamav 0.90 rc1.1
clamav clamav 0.90 rc2
clamav clamav 0.90 rc3
clamav clamav 0.90.1
clamav clamav 0.90 rc1
clamav clamav 0.91
clamav clamav 0.15
clamav clamav 0.20
clamav clamav 0.21
clamav clamav 0.22
clamav clamav 0.23
clamav clamav 0.24
clamav clamav 0.51
clamav clamav 0.52
clamav clamav 0.53
clamav clamav 0.54
clamav clamav 0.60
clamav clamav 0.60p
clamav clamav 0.67
clamav clamav 0.68
clamav clamav 0.68.1
clamav clamav 0.70
clamav clamav 0.71
clamav clamav 0.72
clamav clamav 0.73
clamav clamav 0.74
clamav clamav 0.75
clamav clamav 0.75.1
clamav clamav 0.80
clamav clamav 0.80 rc1
clamav clamav 0.80 rc2
clamav clamav 0.80 rc3
clamav clamav 0.80 rc4
clamav clamav 0.81
clamav clamav 0.81 rc1
clamav clamav 0.82
clamav clamav 0.84
clamav clamav 0.84 rc1
clamav clamav 0.85
clamav clamav 0.85.1
clamav clamav 0.86
clamav clamav 0.86.1
clamav clamav 0.86.2
clamav clamav 0.87.1
clamav clamav 0.88
clamav clamav 0.88.1
clamav clamav 0.88.3
clamav clamav 0.88.4
clamav clamav 0.88.5
clamav clamav 0.88.6
clamav clamav 0.88.7
clamav clamav 0.88.2
clamav clamav 0.90.3
clamav clamav 0.91.2_p0
clamav clamav 0.92_p0
clamav clamav 0.93
clamav clamav 0.90.3_p1
clamav clamav 0.90.3_p0
clamav clamav 0.90.2_p0
clamav clamav 0.90.1_p0
clamav clamav 0.88.7_p0
clamav clamav 0.88.7_p1
clamav clamav 0.12
clamav clamav 0.13
clamav clamav 0.14
clamav clamav 0.14 pre
clamav clamav 0.80 rc
clamav clamav 0.93.1
clamav clamav 0.93.3
clamav clamav 0.91 rc2
clamav clamav 0.91 rc1
clamav clamav 0.93.2
clamav clamav 0.02
clamav clamav 0.03
clamav clamav 0.05
clamav clamav 0.01
clamav clamav 0.10
clamav clamav 0.90.2
gentoo linux *
mandrakesoft mandrake linux corporate server 3.0
mandrakesoft mandrake linux corporate server 4.0
mandrakesoft mandrake linux corporate server 4.0
mandrakesoft mandrake linux corporate server 3.0
mandrakesoft mandrake linux 2007.1
mandrakesoft mandrake linux 2008.0
debian debian linux 4.0
mandrakesoft mandrake linux 2008.0
mandrakesoft mandrake linux 2008.1 x86_64
mandrakesoft mandrake linux 2007.1
apple mac os x server 10.4.11
mandrakesoft mandrake linux 2008.1
apple mac os x server 10.5.5