ClamAV < 0.97 Multiple Vulnerabilities

High Nessus Network Monitor Plugin ID 5796

Synopsis

The remote host is running an anti-virus application that is vulnerable to multiple attack vectors.

Description

Versions of ClamAV earlier than 0.97 are potentially affected by multiple vulnerabilities :

- As-yet unspecified double-free issue involving an error path exists in 'libclamav/vba_extract.c' and 'shared/cdiff.c'. (Bug 2486 and report from &lt;mt*debian.org&gt;)
,br. - 'libclamav/pdf.c' may miss detection. (Bug 2455)

- Multiple as-yet unspecified error path leaks exist in 'clamav-milter/whitelist.c', 'clamscan/manager.c' and 'libclamav/sis.c'. (Report from &lt;mt*debian.org&gt;)

Solution

Upgrade to ClamAV 0.97 or later.

See Also

http://blog.clamav.net/2011/02/clamav-097-has-been-released.html

Plugin Details

Severity: High

ID: 5796

Family: Web Clients

Published: 2011/02/15

Modified: 2016/11/16

Dependencies: 9794

Nessus ID: 51935

Risk Information

Risk Factor: High

CVSSv2

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

CVSSv3

Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS3#AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS3#E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:cisco:clamav

Patch Publication Date: 2011/02/07

Vulnerability Publication Date: 2011/02/07

Reference Information

CVE: CVE-2011-1003

BID: 46470