CVE-2008-1389

libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote attackers to cause a denial of service (application crash) via a malformed CHM file, related to an "invalid memory access."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
clam_anti-virusclamav
𝑥
≤ 0.93.3
clam_anti-virusclamav
0.11
clam_anti-virusclamav
0.12
clam_anti-virusclamav
0.13
clam_anti-virusclamav
0.14
clam_anti-virusclamav
0.14:pre
clam_anti-virusclamav
0.15
clam_anti-virusclamav
0.20
clam_anti-virusclamav
0.21
clam_anti-virusclamav
0.22
clam_anti-virusclamav
0.23
clam_anti-virusclamav
0.24
clam_anti-virusclamav
0.51
clam_anti-virusclamav
0.52
clam_anti-virusclamav
0.53
clam_anti-virusclamav
0.54
clam_anti-virusclamav
0.60
clam_anti-virusclamav
0.60p:p
clam_anti-virusclamav
0.65
clam_anti-virusclamav
0.67
clam_anti-virusclamav
0.68
clam_anti-virusclamav
0.68.1
clam_anti-virusclamav
0.70
clam_anti-virusclamav
0.71
clam_anti-virusclamav
0.72
clam_anti-virusclamav
0.73
clam_anti-virusclamav
0.74
clam_anti-virusclamav
0.75
clam_anti-virusclamav
0.75.1
clam_anti-virusclamav
0.80
clam_anti-virusclamav
0.80:rc
clam_anti-virusclamav
0.80:rc2
clam_anti-virusclamav
0.80:rc3
clam_anti-virusclamav
0.80:rc4
clam_anti-virusclamav
0.81
clam_anti-virusclamav
0.81:rc1
clam_anti-virusclamav
0.82
clam_anti-virusclamav
0.83
clam_anti-virusclamav
0.84
clam_anti-virusclamav
0.84:rc1
clam_anti-virusclamav
0.84:rc2
clam_anti-virusclamav
0.85
clam_anti-virusclamav
0.85.1
clam_anti-virusclamav
0.86
clam_anti-virusclamav
0.86:rc1
clam_anti-virusclamav
0.86.1
clam_anti-virusclamav
0.86.2
clam_anti-virusclamav
0.87
clam_anti-virusclamav
0.87.1
clam_anti-virusclamav
0.88
clam_anti-virusclamav
0.88.1
clam_anti-virusclamav
0.88.2
clam_anti-virusclamav
0.88.3
clam_anti-virusclamav
0.88.4
clam_anti-virusclamav
0.88.5
clam_anti-virusclamav
0.88.6
clam_anti-virusclamav
0.88.7
clam_anti-virusclamav
0.90
clam_anti-virusclamav
0.90.1
clam_anti-virusclamav
0.90.2
clam_anti-virusclamav
0.90.3
clam_anti-virusclamav
0.91
clam_anti-virusclamav
0.91.1
clam_anti-virusclamav
0.91.2
clam_anti-virusclamav
0.92
clam_anti-virusclamav
0.92.1
clam_anti-virusclamav
0.93
clam_anti-virusclamav
0.93.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
clamav
bullseye
0.103.10+dfsg-0+deb11u1
fixed
etch
not-affected
bookworm
1.0.5+dfsg-1~deb12u1
fixed
sid
1.4.1+dfsg-1
fixed
trixie
1.4.1+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
clamav
jaunty
not-affected
intrepid
not-affected
hardy
Fixed 0.94.dfsg.2-1ubuntu0.3~hardy4
released
gutsy
ignored
feisty
ignored
dapper
Fixed 0.94.dfsg.2-1ubuntu0.3~dapper2
released
Common Weakness Enumeration
References