Summary
ClamAV is prone to a double-free memory-corruption vulnerability.
An attacker can exploit this issue to cause denial-of-service conditions. Due to the nature of this issue, arbitrary code execution may be possible
this has not been confirmed.
Versions prior to ClamAV 0.97 are vulnerable.
Solution
Updates are available. Please see the references for more information.
References
Updated on 2017-03-28
Severity
Classification
-
CVE CVE-2011-1003 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Adobe Reader Old Plugin Signature Bypass Vulnerability (Windows)
- Apple Safari WebKit Information Disclosure Vulnerability (Mac OS X)
- Adobe Flash Player Multiple Security Bypass Vulnerabilities - 01 Feb14 (Mac OS X)
- Adobe Reader 'SWF' Information Disclosure Vulnerability (Windows)
- Apache Tomcat servlet/JSP container default files