ClamAV < 0.97 Multiple Vulnerabilities

high Nessus Network Monitor Plugin ID 5796

Synopsis

The remote host is running an anti-virus application that is vulnerable to multiple attack vectors.

Description

Versions of ClamAV earlier than 0.97 are potentially affected by multiple vulnerabilities :

- As-yet unspecified double-free issue involving an error path exists in 'libclamav/vba_extract.c' and 'shared/cdiff.c'. (Bug 2486 and report from <mt*debian.org>)
,br. - 'libclamav/pdf.c' may miss detection. (Bug 2455)

- Multiple as-yet unspecified error path leaks exist in 'clamav-milter/whitelist.c', 'clamscan/manager.c' and 'libclamav/sis.c'. (Report from <mt*debian.org>)

Solution

Upgrade to ClamAV 0.97 or later.

See Also

http://blog.clamav.net/2011/02/clamav-097-has-been-released.html

Plugin Details

Severity: High

ID: 5796

Family: Web Clients

Published: 2/15/2011

Updated: 3/6/2019

Nessus ID: 51935

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS v3

Risk Factor: High

Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:cisco:clamav

Patch Publication Date: 2/7/2011

Vulnerability Publication Date: 2/7/2011

Reference Information

CVE: CVE-2011-1003

BID: 46470