7.5

CVE-2007-0897

Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.

Data is provided by the National Vulnerability Database (NVD)
ClamavClamav Version < 0.90
ApplemacOS X Server Version < 10.4.11
DebianDebian Linux Version3.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5.27% 0.896
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-772 Missing Release of Resource after Effective Lifetime

The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

http://secunia.com/advisories/24183
Vendor Advisory
Broken Link
http://secunia.com/advisories/24187
Patch
Vendor Advisory
Broken Link
http://secunia.com/advisories/24192
Vendor Advisory
Broken Link
http://secunia.com/advisories/24319
Vendor Advisory
Broken Link
http://secunia.com/advisories/24332
Vendor Advisory
Broken Link
http://secunia.com/advisories/24425
Vendor Advisory
Broken Link
http://www.securityfocus.com/bid/22580
Patch
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id?1017659
Third Party Advisory
Broken Link
VDB Entry