Back to search
CVE-2007-3123
Published: Jun 7, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
unrar.c in libclamav in ClamAV before 0.90.3 and 0.91 before 0.91rc1 allows remote attackers to cause a denial of service (core dump) via a crafted RAR file with a modified vm_codesize value, which triggers a heap-based buffer overflow.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
25796
third-party-advisory
x_refsource_SECUNIA
24289
vdb-entry
x_refsource_BID
35522
vdb-entry
x_refsource_OSVDB
SUSE-SA:2007:033
vendor-advisory
x_refsource_SUSE
25525
third-party-advisory
x_refsource_SECUNIA
25523
third-party-advisory
x_refsource_SECUNIA
DSA-1320
vendor-advisory
x_refsource_DEBIAN
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=521
x_refsource_CONFIRM
http://kolab.org/security/kolab-vendor-notice-15.txt
x_refsource_CONFIRM
25688
third-party-advisory
x_refsource_SECUNIA
clamav-rar-dos(34778)
vdb-entry
x_refsource_XF
[Clamav-announce] 20070530 announcing ClamAV 0.90.3
mailing-list
x_refsource_MLIST
http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLog
x_refsource_CONFIRM
GLSA-200706-05
vendor-advisory
x_refsource_GENTOO
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now