CVE-2008-3215

libclamav/petite.c in ClamAV before 0.93.3 allows remote attackers to cause a denial of service via a malformed Petite file that triggers an out-of-bounds memory access. NOTE: this issue exists because of an incomplete fix for CVE-2008-2713.
References
Link Resource
http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html
http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00006.html
http://lurker.clamav.net/message/20080707.155612.ad411b00.en.html
http://secunia.com/advisories/31091
http://secunia.com/advisories/31437
http://secunia.com/advisories/31882
http://security.gentoo.org/glsa/glsa-200808-07.xml
http://svn.clamav.net/websvn/diff.php?repname=clamav-devel&path=/branches/0.93/libclamav/petite.c&rev=3920 Exploit
http://www.mandriva.com/security/advisories?name=MDVSA-2008:166
http://www.openwall.com/lists/oss-security/2008/07/08/5
http://www.openwall.com/lists/oss-security/2008/07/15/1
http://www.us-cert.gov/cas/techalerts/TA08-260A.html US Government Resource
http://www.vupen.com/english/advisories/2008/2584
https://exchange.xforce.ibmcloud.com/vulnerabilities/44200
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00606.html
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00617.html
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1000#c4
http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html
http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00006.html
http://lurker.clamav.net/message/20080707.155612.ad411b00.en.html
http://secunia.com/advisories/31091
http://secunia.com/advisories/31437
http://secunia.com/advisories/31882
http://security.gentoo.org/glsa/glsa-200808-07.xml
http://svn.clamav.net/websvn/diff.php?repname=clamav-devel&path=/branches/0.93/libclamav/petite.c&rev=3920 Exploit
http://www.mandriva.com/security/advisories?name=MDVSA-2008:166
http://www.openwall.com/lists/oss-security/2008/07/08/5
http://www.openwall.com/lists/oss-security/2008/07/15/1
http://www.us-cert.gov/cas/techalerts/TA08-260A.html US Government Resource
http://www.vupen.com/english/advisories/2008/2584
https://exchange.xforce.ibmcloud.com/vulnerabilities/44200
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00606.html
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00617.html
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1000#c4
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:clam_anti-virus:clamav:0.88.2:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.88.4:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.88.5:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.88.6:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.88.7:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.88.7:p0:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.88.7:p1:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.90:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.90.1:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.90.1:p0:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.90.2:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.90.2:p0:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.90.3:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.90.3:p0:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.90.3:p1:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.91.2:p0:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.92:p0:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.92.1:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.93:*:*:*:*:*:*:*

History

21 Nov 2024, 00:48

Type Values Removed Values Added
References () http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html - () http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html -
References () http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00006.html - () http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00006.html -
References () http://lurker.clamav.net/message/20080707.155612.ad411b00.en.html - () http://lurker.clamav.net/message/20080707.155612.ad411b00.en.html -
References () http://secunia.com/advisories/31091 - () http://secunia.com/advisories/31091 -
References () http://secunia.com/advisories/31437 - () http://secunia.com/advisories/31437 -
References () http://secunia.com/advisories/31882 - () http://secunia.com/advisories/31882 -
References () http://security.gentoo.org/glsa/glsa-200808-07.xml - () http://security.gentoo.org/glsa/glsa-200808-07.xml -
References () http://svn.clamav.net/websvn/diff.php?repname=clamav-devel&path=/branches/0.93/libclamav/petite.c&rev=3920 - Exploit () http://svn.clamav.net/websvn/diff.php?repname=clamav-devel&path=/branches/0.93/libclamav/petite.c&rev=3920 - Exploit
References () http://www.mandriva.com/security/advisories?name=MDVSA-2008:166 - () http://www.mandriva.com/security/advisories?name=MDVSA-2008:166 -
References () http://www.openwall.com/lists/oss-security/2008/07/08/5 - () http://www.openwall.com/lists/oss-security/2008/07/08/5 -
References () http://www.openwall.com/lists/oss-security/2008/07/15/1 - () http://www.openwall.com/lists/oss-security/2008/07/15/1 -
References () http://www.us-cert.gov/cas/techalerts/TA08-260A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA08-260A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2008/2584 - () http://www.vupen.com/english/advisories/2008/2584 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/44200 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/44200 -
References () https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00606.html - () https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00606.html -
References () https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00617.html - () https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00617.html -
References () https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1000#c4 - () https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1000#c4 -

Information

Published : 2008-07-18 16:41

Updated : 2024-11-21 00:48


NVD link : CVE-2008-3215

Mitre link : CVE-2008-3215

CVE.ORG link : CVE-2008-3215


JSON object : View

Products Affected

clam_anti-virus

  • clamav
CWE
CWE-399

Resource Management Errors