The OLE2 unpacker in clamd in Clam AntiVirus (ClamAV) 0.87-1 allows remote attackers to cause a denial of service (segmentation fault) via a DOC file with an invalid property tree, which triggers an infinite recursion in the ole2_walk_property_tree function.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade clamav | Jul 30, 2024 | Oct 14, 2005 |
| Gentoo Linux | — | Upgrade app-antivirus/clamav. | Oct 30, 2017 | Oct 14, 2005 |
| Suse | — | Upgrade libclammspack0Upgrade clamav-develUpgrade clamav-docs-htmlUpgrade libfreshclam4Upgrade libfreshclam3Upgrade clamavUpgrade libclamav12Upgrade clamav-milter | Feb 17, 2015 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub