CVE-2008-5050

Off-by-one error in the get_unicode_name function (libclamav/vba_extract.c) in Clam Anti-Virus (ClamAV) before 0.94.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted VBA project file, which triggers a heap-based buffer overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
clam_anti-virusclamav
𝑥
≤ 0.94
clam_anti-virusclamav
0.01
clam_anti-virusclamav
0.02
clam_anti-virusclamav
0.03
clam_anti-virusclamav
0.04
clam_anti-virusclamav
0.05
clam_anti-virusclamav
0.06
clam_anti-virusclamav
0.10
clam_anti-virusclamav
0.11
clam_anti-virusclamav
0.12
clam_anti-virusclamav
0.13
clam_anti-virusclamav
0.14
clam_anti-virusclamav
0.14:pre
clam_anti-virusclamav
0.15
clam_anti-virusclamav
0.20
clam_anti-virusclamav
0.21
clam_anti-virusclamav
0.22
clam_anti-virusclamav
0.23
clam_anti-virusclamav
0.24
clam_anti-virusclamav
0.51
clam_anti-virusclamav
0.52
clam_anti-virusclamav
0.53
clam_anti-virusclamav
0.54
clam_anti-virusclamav
0.60
clam_anti-virusclamav
0.60p:p
clam_anti-virusclamav
0.65
clam_anti-virusclamav
0.67
clam_anti-virusclamav
0.68
clam_anti-virusclamav
0.68.1
clam_anti-virusclamav
0.70
clam_anti-virusclamav
0.71
clam_anti-virusclamav
0.72
clam_anti-virusclamav
0.73
clam_anti-virusclamav
0.74
clam_anti-virusclamav
0.75
clam_anti-virusclamav
0.75.1
clam_anti-virusclamav
0.80
clam_anti-virusclamav
0.80:rc
clam_anti-virusclamav
0.80:rc2
clam_anti-virusclamav
0.80:rc3
clam_anti-virusclamav
0.80:rc4
clam_anti-virusclamav
0.80_rc1:_rc1
clam_anti-virusclamav
0.80_rc2:_rc2
clam_anti-virusclamav
0.80_rc3:_rc3
clam_anti-virusclamav
0.80_rc4:_rc4
clam_anti-virusclamav
0.81
clam_anti-virusclamav
0.81:rc1
clam_anti-virusclamav
0.81_rc1:_rc1
clam_anti-virusclamav
0.82
clam_anti-virusclamav
0.83
clam_anti-virusclamav
0.84
clam_anti-virusclamav
0.84:rc1
clam_anti-virusclamav
0.84:rc2
clam_anti-virusclamav
0.84_rc1:_rc1
clam_anti-virusclamav
0.84_rc2:_rc2
clam_anti-virusclamav
0.85
clam_anti-virusclamav
0.85.1
clam_anti-virusclamav
0.86
clam_anti-virusclamav
0.86:rc1
clam_anti-virusclamav
0.86.1
clam_anti-virusclamav
0.86.2
clam_anti-virusclamav
0.86_rc1:_rc1
clam_anti-virusclamav
0.87
clam_anti-virusclamav
0.87.1
clam_anti-virusclamav
0.88
clam_anti-virusclamav
0.88.1
clam_anti-virusclamav
0.88.2
clam_anti-virusclamav
0.88.3
clam_anti-virusclamav
0.88.4
clam_anti-virusclamav
0.88.5
clam_anti-virusclamav
0.88.6
clam_anti-virusclamav
0.88.7
clam_anti-virusclamav
0.88.7:p0
clam_anti-virusclamav
0.88.7:p1
clam_anti-virusclamav
0.90
clam_anti-virusclamav
0.90.1
clam_anti-virusclamav
0.90.1:p0
clam_anti-virusclamav
0.90.2
clam_anti-virusclamav
0.90.2:p0
clam_anti-virusclamav
0.90.3
clam_anti-virusclamav
0.90.3:p0
clam_anti-virusclamav
0.90.3:p1
clam_anti-virusclamav
0.90_rc1.1:_rc1.1
clam_anti-virusclamav
0.90_rc2:_rc2
clam_anti-virusclamav
0.90_rc3:_rc3
clam_anti-virusclamav
0.90rc1:rc1
clam_anti-virusclamav
0.91
clam_anti-virusclamav
0.91.1
clam_anti-virusclamav
0.91.2
clam_anti-virusclamav
0.91.2:p0
clam_anti-virusclamav
0.91rc1:rc1
clam_anti-virusclamav
0.91rc2:rc2
clam_anti-virusclamav
0.92
clam_anti-virusclamav
0.92:p0
clam_anti-virusclamav
0.92.1
clam_anti-virusclamav
0.93
clam_anti-virusclamav
0.93.1
clam_anti-virusclamav
0.93.2
clam_anti-virusclamav
0.93.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
clamav
bullseye
0.103.10+dfsg-0+deb11u1
fixed
bookworm
1.0.5+dfsg-1~deb12u1
fixed
sid
1.4.1+dfsg-1
fixed
trixie
1.4.1+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
clamav
intrepid
Fixed 0.94.dfsg.1-1ubuntu0.1
released
hardy
Fixed 0.92.1~dfsg2-1.1ubuntu0.3
released
gutsy
Fixed 0.92.1~dfsg2-1.1~gutsy3.1ubuntu1
released
dapper
Fixed 0.92.1~dfsg2-1.1~dapper3.2
released
References