vendor:
ClamAV
by:
Damian Put
7.5
CVSS
HIGH
Denial of Service
20
CWE
Product Name: ClamAV
Affected Version From:
Affected Version To:
Patch Exists: YES
Related CWE: CVE-2006-1618
CPE: a:clamav:clamav
Platforms Tested:
Clam AntiVirus ClamAV CHM Chunk Name Length DoS Vulnerability
This is a vulnerability in ClamAV that allows an attacker to cause a denial of service by sending a specially crafted CHM file. The vulnerability is due to a flaw in the handling of CHM chunk names, which can be exploited to crash the application. The vulnerability was discovered by Damian Put and all credits go to him.
Mitigation:
Apply the latest security updates from the vendor.