Summary
ClamAV is prone to a double-free memory-corruption vulnerability.
An attacker can exploit this issue to cause denial-of-service conditions. Due to the nature of this issue, arbitrary code execution may be possible
this has not been confirmed.
Versions prior to ClamAV 0.97 are vulnerable.
Solution
Updates are available. Please see the references for more information.
References
Updated on 2017-03-28
Severity
Classification
-
CVE CVE-2011-1003 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Apple Safari Multiple Memory Corruption Vulnerabilities-02 Apr14 (Mac OS X)
- Adobe Reader 'file://' URL Information Disclosure Vulnerability Feb07 (Mac OS X)
- Apple Safari JavaScript Implementation Information Disclosure Vulnerability (Mac OS X)
- Apache Tomcat Remote Code Execution Vulnerability - Sep14
- Apple Safari 'background' Remote Denial Of Service Vulnerability