5

CVE-2008-1835

ClamAV before 0.93 allows remote attackers to bypass the scanning enging via a RAR file with an invalid version number, which cannot be parsed by ClamAV but can be extracted by Winrar.

Data is provided by the National Vulnerability Database (NVD)
Clam Anti-virusClamav Version <= 0.92.1
Clam Anti-virusClamav Version0.15
Clam Anti-virusClamav Version0.20
Clam Anti-virusClamav Version0.21
Clam Anti-virusClamav Version0.22
Clam Anti-virusClamav Version0.23
Clam Anti-virusClamav Version0.24
Clam Anti-virusClamav Version0.51
Clam Anti-virusClamav Version0.52
Clam Anti-virusClamav Version0.53
Clam Anti-virusClamav Version0.54
Clam Anti-virusClamav Version0.60
Clam Anti-virusClamav Version0.60p
Clam Anti-virusClamav Version0.65
Clam Anti-virusClamav Version0.67
Clam Anti-virusClamav Version0.68
Clam Anti-virusClamav Version0.68.1
Clam Anti-virusClamav Version0.70
Clam Anti-virusClamav Version0.71
Clam Anti-virusClamav Version0.72
Clam Anti-virusClamav Version0.73
Clam Anti-virusClamav Version0.74
Clam Anti-virusClamav Version0.75
Clam Anti-virusClamav Version0.75.1
Clam Anti-virusClamav Version0.80
Clam Anti-virusClamav Version0.80_rc1
Clam Anti-virusClamav Version0.80_rc2
Clam Anti-virusClamav Version0.80_rc3
Clam Anti-virusClamav Version0.80_rc4
Clam Anti-virusClamav Version0.81
Clam Anti-virusClamav Version0.81_rc1
Clam Anti-virusClamav Version0.82
Clam Anti-virusClamav Version0.83
Clam Anti-virusClamav Version0.84
Clam Anti-virusClamav Version0.84_rc1
Clam Anti-virusClamav Version0.84_rc2
Clam Anti-virusClamav Version0.85
Clam Anti-virusClamav Version0.85.1
Clam Anti-virusClamav Version0.86
Clam Anti-virusClamav Version0.86.1
Clam Anti-virusClamav Version0.86.2
Clam Anti-virusClamav Version0.86_rc1
Clam Anti-virusClamav Version0.87
Clam Anti-virusClamav Version0.87.1
Clam Anti-virusClamav Version0.88
Clam Anti-virusClamav Version0.88.1
Clam Anti-virusClamav Version0.88.3
Clam Anti-virusClamav Version0.88.4
Clam Anti-virusClamav Version0.88.5
Clam Anti-virusClamav Version0.88.6
Clam Anti-virusClamav Version0.88.7
Clam Anti-virusClamav Version0.90
Clam Anti-virusClamav Version0.90.1
Clam Anti-virusClamav Version0.90.2
Clam Anti-virusClamav Version0.90_rc1.1
Clam Anti-virusClamav Version0.90_rc2
Clam Anti-virusClamav Version0.90_rc3
Clam Anti-virusClamav Version0.90rc1
Clam Anti-virusClamav Version0.91
Clam Anti-virusClamav Version0.91.1
Clam Anti-virusClamav Version0.91.2
Clam Anti-virusClamav Version0.91rc1
Clam Anti-virusClamav Version0.91rc2
Clam Anti-virusClamav Version0.92
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.81% 0.811
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.