The rfc2231 function in message.c in libclamav in ClamAV before 0.93 allows remote attackers to cause a denial of service (crash) via a crafted message that produces a string that is not null terminated, which triggers a buffer over-read.
2008-04-16T16:05:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | clam_anti-virus | clamav | 0.90 | Yes |
| Application | clam_anti-virus | clamav | 0.90.1 | Yes |
| Application | clam_anti-virus | clamav | 0.90_rc1.1 | Yes |
| Application | clam_anti-virus | clamav | 0.90_rc2 | Yes |
| Application | clam_anti-virus | clamav | 0.90_rc3 | Yes |
| Application | clam_anti-virus | clamav | 0.90rc1 | Yes |
| Application | clam_anti-virus | clamav | 0.91 | Yes |
| Application | clam_anti-virus | clamav | 0.92 | Yes |