libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.
References
Configurations
History
21 Nov 2024, 01:02
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html - Mailing List, Third Party Advisory | |
References | () http://osvdb.org/53461 - Broken Link | |
References | () http://secunia.com/advisories/34716 - Third Party Advisory | |
References | () http://secunia.com/advisories/36701 - Third Party Advisory | |
References | () http://support.apple.com/kb/HT3865 - Third Party Advisory | |
References | () http://www.debian.org/security/2009/dsa-1771 - Third Party Advisory | |
References | () http://www.mandriva.com/security/advisories?name=MDVSA-2009:097 - Third Party Advisory | |
References | () http://www.openwall.com/lists/oss-security/2009/04/07/6 - Mailing List, Third Party Advisory | |
References | () http://www.securityfocus.com/bid/34357 - Third Party Advisory, VDB Entry | |
References | () http://www.ubuntu.com/usn/usn-754-1 - Third Party Advisory | |
References | () http://www.vupen.com/english/advisories/2009/0934 - Third Party Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/49846 - Third Party Advisory, VDB Entry | |
References | () https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1462 - Broken Link, Issue Tracking |
10 Feb 2022, 16:25
Type | Values Removed | Values Added |
---|---|---|
References | (CONFIRM) https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1462 - Broken Link, Issue Tracking | |
References | (SECUNIA) http://secunia.com/advisories/36701 - Third Party Advisory | |
References | (UBUNTU) http://www.ubuntu.com/usn/usn-754-1 - Third Party Advisory | |
References | (VUPEN) http://www.vupen.com/english/advisories/2009/0934 - Third Party Advisory | |
References | (DEBIAN) http://www.debian.org/security/2009/dsa-1771 - Third Party Advisory | |
References | (MLIST) http://www.openwall.com/lists/oss-security/2009/04/07/6 - Mailing List, Third Party Advisory | |
References | (BID) http://www.securityfocus.com/bid/34357 - Third Party Advisory, VDB Entry | |
References | (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/49846 - Third Party Advisory, VDB Entry | |
References | (CONFIRM) http://support.apple.com/kb/HT3865 - Third Party Advisory | |
References | (OSVDB) http://osvdb.org/53461 - Broken Link | |
References | (MANDRIVA) http://www.mandriva.com/security/advisories?name=MDVSA-2009:097 - Third Party Advisory | |
References | (SECUNIA) http://secunia.com/advisories/34716 - Third Party Advisory | |
References | (APPLE) http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html - Mailing List, Third Party Advisory | |
CWE | CWE-835 | |
CPE | cpe:2.3:a:clamav:clamav:0.91_rc1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.88.7_p1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.68:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.93.2:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.52:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.90_rc1.1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.87.1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.88.1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.91.1:*:*:*:*:*:*:* cpe:2.3:a:clamavs:clamav:0.06:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.80_rc:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.86.1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.90.1_p0:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.71:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.88.6:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.80_rc2:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.81_rc1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.90.2:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.53:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.92.1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.03:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.88.7_p0:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.90.3_p1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.90.3:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.90:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.90_rc2:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.92:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.24:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.51:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.84_rc1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.86:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.92_p0:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.75:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.94:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.88:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.15:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.12:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.68.1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.01:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.91.2:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.90.3_p0:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.91_rc2:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.93.3:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.90_rc1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.93:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.81:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.05:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.73:*:*:*:*:*:*:* cpe:2.3:a:clamavclamav:0.11:*:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.80_rc3:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.54:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.8_:rc3:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.83:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.91:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.88.7:*:*:*:*:*:*:* cpe:2.3:a:cclamav:clamav:0.14:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.75.1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.67:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.84:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.21:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.13:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.80:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.85.1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.93.1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.88.5:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.88.4:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.70:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.72:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.86_rc1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.82:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.60:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.88.2:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.87:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.20:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.22:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.74:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.90_rc3:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.65:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.90.1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.9_rc1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.85:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.10:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.88.3:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.60p:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.80_rc1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.91.2_p0:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.02:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.90.2_p0:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.86.2:*:*:*:*:*:*:* cpe:2.3:a:clamavs:clamav:0.24:*:*:*:*:*:*:* cpe:2.3:a:clamavclamav:0.80_rc4:*:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.94.1:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.84_rc2:*:*:*:*:*:*:* cpe:2.3:a:clamavs:clamav:0.04:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:0.14:pre:*:*:*:*:*:* |
cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:* |
Information
Published : 2009-04-08 16:30
Updated : 2024-11-21 01:02
NVD link : CVE-2009-1270
Mitre link : CVE-2009-1270
CVE.ORG link : CVE-2009-1270
JSON object : View
Products Affected
clamav
- clamav
debian
- debian_linux
canonical
- ubuntu_linux
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')