Heap-based buffer overflow in the pefromupx function in libclamav/upx.c in Clam AntiVirus (ClamAV) 0.81 through 0.88.3 allows remote attackers to execute arbitrary code via a crafted UPX packed file containing sections with large rsize values.
2006-08-08T20:04:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | clamav | clamav | 0.81 | Yes |
Application | clamav | clamav | 0.81 | Yes |
Application | clamav | clamav | 0.82 | Yes |
Application | clamav | clamav | 0.83 | Yes |
Application | clamav | clamav | 0.84 | Yes |
Application | clamav | clamav | 0.84 | Yes |
Application | clamav | clamav | 0.84 | Yes |
Application | clamav | clamav | 0.85 | Yes |
Application | clamav | clamav | 0.85.1 | Yes |
Application | clamav | clamav | 0.86 | Yes |
Application | clamav | clamav | 0.86 | Yes |
Application | clamav | clamav | 0.86.1 | Yes |
Application | clamav | clamav | 0.86.2 | Yes |
Application | clamav | clamav | 0.87 | Yes |
Application | clamav | clamav | 0.87.1 | Yes |
Application | clamav | clamav | 0.88 | Yes |
Application | clamav | clamav | 0.88.1 | Yes |
Application | clamav | clamav | 0.88.2 | Yes |
Application | clamav | clamav | 0.88.3 | Yes |