Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Integer signedness error in the (1) cab_unstore and (2) cab_extract functions in libclamav/cab.c in Clam AntiVirus (ClamAV) before 0.90.2 allow remote attackers to execute arbitrary code via a crafted CHM file that contains a negative integer, which passes a signed comparison and leads to a stack-based buffer overflow.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Clam AntiVirus ClamAV sizeof()权限提升漏洞
Vulnerability Description
Clam AntiVirus是Unix的GPL杀毒工具包,很多邮件网关产品都在使用。 ClamAV libclamav库中的cab_unstore()函数中存在缓冲区溢出漏洞,远程攻击者可能利用此漏洞控制用户机器。 该函数从报文中获取了32位的有符型整数并与目标缓冲区的sizeof()做比较,但sizeof()返回值被错误地转换成有符型整数。如果提供了负数值的话,攻击者就可以导致比较成功,触发可利用的栈溢出。成功利用这个漏洞可能导致以使用libclamav的进程的权限执行任意代码。 此外,libclama
CVSS Information
N/A
Vulnerability Type
N/A