PT-2004-2775 · Clam · Clam Antivirus

Published

2004-03-30

·

Updated

2017-07-11

·

CVE-2004-1876

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Clam AntiVirus daemon (clamd) versions prior to 0.70
Description The issue concerns the "%f" feature in the VirusEvent directive, which allows local users to execute arbitrary commands via shell metacharacters in a file name.
Recommendations For versions prior to 0.70, update to version 0.70 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1876

Affected Products

Clam Antivirus