Title : Clam AntiVirus Malformed FSG/TNEF/CAB File Handling Vulnerabilities VUPEN ID : VUPEN/ADV-2005-2294 CVE ID : CVE-2005-3303 - CVE-2005-3500 - CVE-2005-3501
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-11-04
Technical Description
Multiple vulnerabilities were identified in Clam AntiVirus, which could be exploited by remote attackers to execute arbitrary commands or cause a denial of service.
The first issue is due to a buffer overflow error in "libclamav/fsg.c" when unpacking malformed FSG files, which could be exploited by remote attackers to execute arbitrary commands via a specially crafted file.
The second vulnerability is due to an infinite loop in "libclamav/tnef.c" when processing malformed TNEF files, which could be exploited by remote attackers to cause a denial of service.
The third flaw is due to an infinite loop in "libclamav/mspack/cabd.c" when processing malformed CAB files, which could be exploited by remote attackers to cause a denial of service.