The Microsoft CHM file parser in ClamAV 0.96.4 and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a crafted reset interval in the LZXC header of a CHM file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CHM parser implementations.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade clamav | Jul 30, 2024 | Mar 21, 2012 |
| Freebsd | — | Upgrade clamav-develUpgrade clamav | Dec 10, 2025 | Jun 16, 2012 |
| Suse | — | Upgrade libfreshclam3Upgrade libclamav7Upgrade libclammspack0Upgrade clamav-docs-htmlUpgrade libclamav12Upgrade clamav-milterUpgrade clamavUpgrade libfreshclam4Upgrade clamav-devel | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade clamav-daemonUpgrade libclamav6Upgrade clamav | Nov 8, 2024 | Mar 21, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub