The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (resource consumption) via an OLE2 file with (1) a large property size or (2) a loop in the FAT file block chain that triggers an infinite loop, as demonstrated via a crafted DOC file.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade clamav | Jul 30, 2024 | May 14, 2007 |
| Freebsd | — | Upgrade clamav | Dec 10, 2025 | Jun 19, 2007 |
| Gentoo Linux | — | Upgrade app-antivirus/clamav. | Oct 30, 2017 | May 14, 2007 |
| Suse | — | Upgrade clamavUpgrade clamav-dbUpgrade suse-release | Feb 17, 2015 | May 14, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub