>> ClamAV Petite File Processing Remote Denial of Service Vulnerability
Title : ClamAV Petite File Processing Remote Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2008-1855 CVE ID : CVE-2008-2713 - CVE-2008-3215 CWE ID : CWE-125
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-06-17
Technical Description
A vulnerability has been identified in ClamAV, which could be exploited by remote attackers or malware to cause a denial of service. This issue is caused by an an out-of-bounds read related to the "libclamav/petite.c" file when processing malformed Petite compressed files, which could be exploited by attackers to crash an affected application via a malicious and specially crafted Petite file.