CVE-2005-2450
Summary
| CVE | CVE-2005-2450 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-08-03 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Multiple integer overflows in the (1) TNEF, (2) CHM, or (3) FSG file format processors in libclamav for Clam AntiVirus (ClamAV) 0.86.1 and earlier allow remote attackers to gain privileges via a crafted e-mail message. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Clam Anti-virus | Clamav | 0.85 | All | All | All |
| Application | Clam Anti-virus | Clamav | 0.85.1 | All | All | All |
| Application | Clam Anti-virus | Clamav | 0.86 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Gentoo Linux Documentation -- Clam AntiVirus: Integer overflows | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Security Advisory SA16229 - Gentoo update for clamav - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Secunia - Advisories - Mandriva update for clamav | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| www.osvdb.org/18259 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| ClamAV Multiple Integer Overflow Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| www.osvdb.org/18258 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Secunia - Advisories - Clam AntiVirus Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Secunia - Advisories - Debian update for clamav | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| 'ClamAV Multiple Rem0te Buffer Overflows' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| SourceForge.net: Files | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | Patch |
| Secunia - Advisories - Conectiva update for clamav | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| www.osvdb.org/18257 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Home - Conectiva | af854a3a-2127-422b-91ae-364da2661108 | distro.conectiva.com.br | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.