Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.
References
Configurations
History
No history.
Information
Published : 2007-02-16 19:28
Updated : 2024-02-09 02:48
NVD link : CVE-2007-0897
Mitre link : CVE-2007-0897
CVE.ORG link : CVE-2007-0897
JSON object : View
Products Affected
clamav
- clamav
apple
- mac_os_x_server
debian
- debian_linux
CWE
CWE-772
Missing Release of Resource after Effective Lifetime