PT-2008-6862 · Debian+1 · Debian+1

Damian Put

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2008-2713

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions libclamav versions prior to 0.93.1
Description The issue concerns multiple vulnerabilities in the libclamav package of the Debian GNU/Linux operating system, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. Specifically, a crafted Petite file can trigger an out-of-bounds read in the petite.c file of ClamAV, causing a denial of service.
Recommendations For versions prior to 0.93.1, update to version 0.93.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the petite.c file or disabling the handling of Petite files until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00786
BDU:2015-02005
CVE-2008-2713
DSA-1616-2
DTSA-138-1
OPENSUSE-SU-2024:10685-1

Affected Products

Debian
Libclamav