PT-2008-6863 · Cisco · Clamav

Published

1970-01-01

·

Updated

2017-08-08

·

CVE-2008-3215

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions ClamAV versions prior to 0.93.3
Description The issue allows remote attackers to cause a denial of service via a malformed file that triggers an out-of-bounds memory access. This can lead to disruption of protected information and can be exploited remotely.
Recommendations For versions prior to 0.93.3, update to version 0.93.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the libclamav module to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00786
BDU:2015-02005
CVE-2008-3215
DSA-1616-2

Affected Products

Clamav