CVE-2005-3501

Description

The cabd_find function in cabd.c of the libmspack library (mspack) for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted CAB file that causes cabd_find to be called with a zero length.

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
7.361

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Clamav 0.01Windows
Multiple Vulnerabilities are affected in Clamav 0.02Windows
Multiple Vulnerabilities are affected in Clamav 0.03Windows
Multiple Vulnerabilities are affected in Clamav 0.05Windows
Multiple Vulnerabilities are affected in Clamav 0.10Windows
Multiple Vulnerabilities are affected in Clamav 0.12Windows
Multiple Vulnerabilities are affected in Clamav 0.13Windows
Multiple Vulnerabilities are affected in Clamav 0.14Windows
Multiple Vulnerabilities are affected in Clamav 0.15Windows
Multiple Vulnerabilities are affected in Clamav 0.20Windows
Multiple Vulnerabilities are affected in Clamav 0.21Windows
Multiple Vulnerabilities are affected in Clamav 0.22Windows
Multiple Vulnerabilities are affected in Clamav 0.23Windows
Multiple Vulnerabilities are affected in Clamav 0.24Windows
Multiple Vulnerabilities are affected in Clamav 0.3Windows
Multiple Vulnerabilities are affected in Clamav 0.51Windows
Multiple Vulnerabilities are affected in Clamav 0.52Windows
Multiple Vulnerabilities are affected in Clamav 0.53Windows
Multiple Vulnerabilities are affected in Clamav 0.54Windows
Multiple Vulnerabilities are affected in Clamav 0.60Windows
Multiple Vulnerabilities are affected in Clamav 0.60pWindows
Multiple Vulnerabilities are affected in Clamav 0.65Windows
Multiple Vulnerabilities are affected in Clamav 0.66Windows
Multiple Vulnerabilities are affected in Clamav 0.67Windows
Multiple Vulnerabilities are affected in Clamav 0.67-1Windows
Multiple Vulnerabilities are affected in Clamav 0.68Windows
Multiple Vulnerabilities are affected in Clamav 0.68.1Windows
Multiple Vulnerabilities are affected in Clamav 0.70Windows
Multiple Vulnerabilities are affected in Clamav 0.71Windows
Multiple Vulnerabilities are affected in Clamav 0.72Windows
Multiple Vulnerabilities are affected in Clamav 0.73Windows
Multiple Vulnerabilities are affected in Clamav 0.74Windows
Multiple Vulnerabilities are affected in Clamav 0.75Windows
Multiple Vulnerabilities are affected in Clamav 0.75.1Windows
Multiple Vulnerabilities are affected in Clamav 0.8Windows
Multiple Vulnerabilities are affected in Clamav 0.80Windows
Multiple Vulnerabilities are affected in Clamav 0.80_rcWindows
Multiple Vulnerabilities are affected in Clamav 0.81Windows
Multiple Vulnerabilities are affected in Clamav 0.82Windows
Multiple Vulnerabilities are affected in Clamav 0.83Windows
Multiple Vulnerabilities are affected in Clamav 0.84Windows
Multiple Vulnerabilities are affected in Clamav 0.85Windows
Multiple Vulnerabilities are affected in Clamav 0.85.1Windows
Multiple Vulnerabilities are affected in Clamav 0.86Windows
Multiple Vulnerabilities are affected in Clamav 0.86.1Windows
Multiple Vulnerabilities are affected in Clamav 0.86.2Windows
Multiple Vulnerabilities are affected in Clamav 0.87Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234