>> ClamAV "cli_check_jpeg_exploit()" Denial of Service Vulnerability
Title : ClamAV "cli_check_jpeg_exploit()" Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2008-3311 CVE ID : CVE-2008-5314 CWE ID : CWE-674
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-12-02
Technical Description
A vulnerability has been identified in ClamAV (Clam AntiVirus), which could be exploited by attackers or malware to cause a denial of service. This issue is caused by an infinite recursion in the "cli_check_jpeg_exploit()" [libclamav/special.c] function when parsing a malformed image, which could allow attackers to trigger a stack overflow and crash a vulnerable application via a malicious image file.