ClamAV < 0.97 Multiple Vulnerabilities

High Nessus Network Monitor Plugin ID 5796


The remote host is running an anti-virus application that is vulnerable to multiple attack vectors.


Versions of ClamAV earlier than 0.97 are potentially affected by multiple vulnerabilities :

- As-yet unspecified double-free issue involving an error path exists in 'libclamav/vba_extract.c' and 'shared/cdiff.c'. (Bug 2486 and report from &lt;mt*;)
,br. - 'libclamav/pdf.c' may miss detection. (Bug 2455)

- Multiple as-yet unspecified error path leaks exist in 'clamav-milter/whitelist.c', 'clamscan/manager.c' and 'libclamav/sis.c'. (Report from &lt;mt*;)


Upgrade to ClamAV 0.97 or later.

See Also

Plugin Details

Severity: High

ID: 5796

Family: Web Clients

Published: 2011/02/15

Modified: 2016/11/16

Dependencies: 9794

Nessus ID: 51935

Risk Information

Risk Factor: High


Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C


Base Score: 7.3

Temporal Score: 6.4


Temporal Vector: CVSS3#E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:cisco:clamav

Patch Publication Date: 2011/02/07

Vulnerability Publication Date: 2011/02/07

Reference Information

CVE: CVE-2011-1003

BID: 46470