CVE-2007-0897

Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.
Configurations

Configuration 1 (hide)

cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2007-02-16 19:28

Updated : 2024-02-09 02:48


NVD link : CVE-2007-0897

Mitre link : CVE-2007-0897

CVE.ORG link : CVE-2007-0897


JSON object : View

Products Affected

clamav

  • clamav

apple

  • mac_os_x_server

debian

  • debian_linux
CWE
CWE-772

Missing Release of Resource after Effective Lifetime