iDEFENSE Security Advisory 2005-11-04.1...

- AV AC AU C I A
发布: 2005-11-05
修订: 2025-04-13

iDEFENSE Security Advisory 11.04.05 - Remote exploitation of a design error in Clam AntiVirus ClamAV allows attackers to cause a denial of service (DoS) condition. The vulnerability specifically exists in the tnef_attachment function within tnef.c. A user controlled value is used to fseek into the file that is being processed; this allows a user to specify the same block for scanning repeatedly, thus leading to an infinite loop. iDEFENSE has confirmed this vulnerability on ClamAV 0.86.1. All previous versions are suspected vulnerable to this issue.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息