PT-2007-5729 · Cisco · Clamav

Publicado

2007-08-28

·

Atualizado

2018-10-15

·

CVE-2007-4560

CVSS v2.0

7.6

Alta

VetorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ClamAV versions prior to 0.91.2
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters in a certain popen call, involving the recipient field of sendmail, when clamav-milter is run in black hole mode.
Recommendations For versions prior to 0.91.2, update to version 0.91.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the clamav-milter in black hole mode to minimize the risk of exploitation.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-4560
DSA-1366-1

Produtos afetados

Clamav