MEDIUM
v0.96): Memory corruption by scanning Quantum-compressed file(s)
Published Apr 8, 2010
5.0
MEDIUMCVSS 2.0
EPSS 3.35%
Description
The qtm_decompress function in libclamav/mspack.c in ClamAV before 0.96 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted CAB archive that uses the Quantum (aka .Q) compression format. NOTE: some of these details are obtained from third party information.
Affected products
No data.
OR
- ≤ 0.96
- 0.01
- 0.02
- 0.3
- 0.03
- 0.05
- 0.9
- 0.10
- 0.12
- 0.13
- 0.14
- 0.14
- 0.15
- 0.20
- 0.21
- 0.22
- 0.23
- 0.24
- 0.51
- 0.52
- 0.53
- 0.54
- 0.60
- 0.60p
- 0.65
- 0.66
- 0.67
- 0.67-1
- 0.68
- 0.68.1
- 0.70
- 0.70
- 0.71
- 0.72
- 0.73
- 0.74
- 0.75
- 0.75.1
- 0.80
- 0.80
- 0.80
- 0.80
- 0.80
- 0.81
- 0.82
- 0.83
- 0.84
- 0.84
- 0.84
- 0.85
- 0.85.1
- 0.86
- 0.86
- 0.86.1
- 0.86.2
- 0.87
- 0.87.1
- 0.88
- 0.88.1
- 0.88.2
- 0.88.3
- 0.88.4
- 0.88.5
- 0.88.6
- 0.88.7
- 0.90
- 0.90
- 0.90
- 0.90
- 0.90
- 0.90.1
- 0.90.2
- 0.90.3
- 0.91
- 0.91
- 0.91
- 0.91.1
- 0.91.2
- 0.92
- 0.92.1
- 0.93
- 0.93.1
- 0.93.2
- 0.93.3
- 0.94
- 0.94.1
- 0.94.2
- 0.95
- 0.95
- 0.95
- 0.95.1
- 0.95.2
- 0.95.3
- 0.96
- 0.04
- 0.06
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (20)
- http://git.clamav.net/gitweb?p=clamav-devel.git%3Ba=blob_plain%3Bf=ChangeLog%3Bhb=clamav-0.96 x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/39293 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/39329 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/39656 third-party-advisoryx_refsource_SECUNIA
- http://support.apple.com/kb/HT4312 x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:082 vendor-advisoryx_refsource_MANDRIVA
- http://www.securityfocus.com/bid/39262 vdb-entryx_refsource_BIDPatch
- http://www.ubuntu.com/usn/USN-926-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2010/0827 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2010/0832 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2010/0909 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2010/1001 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2010/1206 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-1311 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=580468 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2010-1311
- https://www.cve.org/CVERecord?id=CVE-2010-1311
- https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1771 x_refsource_CONFIRM
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 8, 2010
Updated Aug 7, 2024
Reserved Apr 8, 2010
Link CVE-2010-1311
CISA Vulnrichment
Updated n/a