Vulnerability Description
libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote attackers to cause a denial of service (application crash) via a malformed CHM file, related to an "invalid memory access."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Clam Anti-Virus | Clamav | <= 0.93.3 |
Related Weaknesses (CWE)
References
- http://int21.de/cve/CVE-2008-1389-clamav-chd.html
- http://kolab.org/security/kolab-vendor-notice-22.txt
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.html
- http://secunia.com/advisories/31725Vendor Advisory
- http://secunia.com/advisories/31906
- http://secunia.com/advisories/31982
- http://secunia.com/advisories/32030
- http://secunia.com/advisories/32222
- http://secunia.com/advisories/32699
- http://security.gentoo.org/glsa/glsa-200809-18.xml
- http://sourceforge.net/project/shownotes.php?group_id=86638&release_id=623661Patch
- http://support.apple.com/kb/HT3216
- http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLog
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:189
FAQ
What is CVE-2008-1389?
CVE-2008-1389 is a vulnerability with a CVSS score of 5.0 (MEDIUM). libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote attackers to cause a denial of service (application crash) via a malformed CHM file, related to an "invalid memory access."
How severe is CVE-2008-1389?
CVE-2008-1389 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-1389?
Check the references section above for vendor advisories and patch information. Affected products include: Clam Anti-Virus Clamav.