ClamAV Recursion Level Handling Denial of Service Vulnerability
BID:50183
Info
ClamAV Recursion Level Handling Denial of Service Vulnerability
| Bugtraq ID: | 50183 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2011-3627 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 08 2011 12:00AM |
| Updated: | Apr 13 2015 09:16PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Clam Anti-Virus ClamAV 0.96.5 Clam Anti-Virus ClamAV 0.96.4 Clam Anti-Virus ClamAV 0.96.3 Clam Anti-Virus ClamAV 0.96.2 Clam Anti-Virus ClamAV 0.96.1 Clam Anti-Virus ClamAV 0.95.2 Clam Anti-Virus ClamAV 0.95.1 Clam Anti-Virus ClamAV 0.94.2 Clam Anti-Virus ClamAV 0.94.1 Clam Anti-Virus ClamAV 0.93.3 Clam Anti-Virus ClamAV 0.93.1 Clam Anti-Virus ClamAV 0.92.1 Clam Anti-Virus ClamAV 0.91.2 Clam Anti-Virus ClamAV 0.91.1 Clam Anti-Virus ClamAV 0.90.3 Clam Anti-Virus ClamAV 0.90.2 Clam Anti-Virus ClamAV 0.90.1 Clam Anti-Virus ClamAV 0.90 Clam Anti-Virus ClamAV 0.97.2 Clam Anti-Virus ClamAV 0.97 Clam Anti-Virus ClamAV 0.96 Clam Anti-Virus ClamAV 0.95 Clam Anti-Virus ClamAV 0.94 Clam Anti-Virus ClamAV 0.93 Clam Anti-Virus ClamAV 0.92 Clam Anti-Virus ClamAV 0.91 |
| Not Vulnerable: |
Clam Anti-Virus ClamAV 0.97.3 |
Discussion
ClamAV Recursion Level Handling Denial of Service Vulnerability
ClamAV is prone to a denial-of-service vulnerability.
Attackers may exploit this issue to crash the affected application, denying service to legitimate users.
Versions prior to ClamAV 0.97.3 are vulnerable.
ClamAV is prone to a denial-of-service vulnerability.
Attackers may exploit this issue to crash the affected application, denying service to legitimate users.
Versions prior to ClamAV 0.97.3 are vulnerable.
Exploit / POC
ClamAV Recursion Level Handling Denial of Service Vulnerability
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at [email protected].
Solution / Fix
ClamAV Recursion Level Handling Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
ClamAV Recursion Level Handling Denial of Service Vulnerability
References:
References:
- ClamAV Homepage (ClamAV)
- CVE request: recursion level crash in clamav before 0.97.3 (ClamAV)
- fix recursion level crash (ClamAV)