MEDIUM
The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (resource consumption) via an OLE2 file with (1) a large property size or (2) a loop in the FAT file block chain that triggers an infinite loop, as demonstrated via a crafted DOC file
Published May 14, 2007
4.3
MEDIUMCVSS 2.0
EPSS 3.24%
Description
The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (resource consumption) via an OLE2 file with (1) a large property size or (2) a loop in the FAT file block chain that triggers an infinite loop, as demonstrated via a crafted DOC file.
Affected products
No data.
Configuration 2
OR
- 3.1
- 4.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (18)
- http://article.gmane.org/gmane.comp.security.virus.clamav.devel/2853 x_refsource_MISCBroken Link
- http://kolab.org/security/kolab-vendor-notice-15.txt x_refsource_CONFIRMBroken Link
- http://lurker.clamav.net/message/20070418.111144.0df6c5d3.en.html mailing-listx_refsource_MLISTBroken Link
- http://secunia.com/advisories/25244 third-party-advisoryx_refsource_SECUNIAPatchThird Party Advisory
- http://secunia.com/advisories/25523 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/25525 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/25553 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/25558 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/25688 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/25796 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://security.gentoo.org/glsa/glsa-200706-05.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLog x_refsource_CONFIRMBroken Link
- http://www.debian.org/security/2007/dsa-1320 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:115 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.novell.com/linux/security/advisories/2007_33_clamav.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://www.securityfocus.com/bid/24316 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.trustix.org/errata/2007/0020/ vendor-advisoryx_refsource_TRUSTIXBroken Link
- http://www.vupen.com/english/advisories/2007/1776 vdb-entryx_refsource_VUPENPermissions Required
| Link | Providers | Tags |
|---|---|---|
| http://article.gmane.org/gmane.comp.security.virus.clamav.devel/2853 | x_refsource_MISCBroken Link | |
| http://kolab.org/security/kolab-vendor-notice-15.txt | x_refsource_CONFIRMBroken Link | |
| http://lurker.clamav.net/message/20070418.111144.0df6c5d3.en.html | mailing-listx_refsource_MLISTBroken Link | |
| http://secunia.com/advisories/25244 | third-party-advisoryx_refsource_SECUNIAPatchThird Party Advisory | |
| http://secunia.com/advisories/25523 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/25525 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/25553 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/25558 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/25688 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/25796 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://security.gentoo.org/glsa/glsa-200706-05.xml | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLog | x_refsource_CONFIRMBroken Link | |
| http://www.debian.org/security/2007/dsa-1320 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| http://www.mandriva.com/security/advisories?name=MDKSA-2007:115 | vendor-advisoryx_refsource_MANDRIVAThird Party Advisory | |
| http://www.novell.com/linux/security/advisories/2007_33_clamav.html | vendor-advisoryx_refsource_SUSEThird Party Advisory | |
| http://www.securityfocus.com/bid/24316 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.trustix.org/errata/2007/0020/ | vendor-advisoryx_refsource_TRUSTIXBroken Link | |
| http://www.vupen.com/english/advisories/2007/1776 | vdb-entryx_refsource_VUPENPermissions Required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 14, 2007
Updated Aug 7, 2024
Reserved May 14, 2007
Link CVE-2007-2650
CISA Vulnrichment
Updated n/a