The MS-Expand file handling in Clam AntiVirus (ClamAV) before 0.86 allows remote attackers to cause a denial of service (file descriptor and memory consumption) via a crafted file that causes repeated errors in the cli_msexpand function.
2005-07-05T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | clam_anti-virus | clamav | 0.81 | Yes |
| Application | clam_anti-virus | clamav | 0.82 | Yes |
| Application | clam_anti-virus | clamav | 0.83 | Yes |
| Application | clam_anti-virus | clamav | 0.84_rc1 | Yes |
| Application | clam_anti-virus | clamav | 0.84_rc2 | Yes |
| Application | clam_anti-virus | clamav | 0.85 | Yes |
| Application | clam_anti-virus | clamav | 0.85.1 | Yes |