4.3

CVE-2008-1836

The rfc2231 function in message.c in libclamav in ClamAV before 0.93 allows remote attackers to cause a denial of service (crash) via a crafted message that produces a string that is not null terminated, which triggers a buffer over-read.

Data is provided by the National Vulnerability Database (NVD)
Clam Anti-virusClamav Version0.90
Clam Anti-virusClamav Version0.90.1
Clam Anti-virusClamav Version0.90_rc1.1
Clam Anti-virusClamav Version0.90_rc2
Clam Anti-virusClamav Version0.90_rc3
Clam Anti-virusClamav Version0.90rc1
Clam Anti-virusClamav Version0.91
Clam Anti-virusClamav Version0.92
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5.43% 0.891
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P