PT-2008-6862 · Debian+1 · Debian+1

Damian Put

·

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2008-2713

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions libclamav versions prior to 0.93.1
Description The issue concerns multiple vulnerabilities in the libclamav package of the Debian GNU/Linux operating system, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. Specifically, a crafted Petite file can trigger an out-of-bounds read in the petite.c file of ClamAV, causing a denial of service.
Recommendations For versions prior to 0.93.1, update to version 0.93.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the petite.c file or disabling the handling of Petite files until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-00786
BDU:2015-02005
CVE-2008-2713
DSA-1616-2
DTSA-138-1
OPENSUSE-SU-2024:10685-1

Produtos afetados

Debian
Libclamav