Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
unrar.c in libclamav in ClamAV before 0.90.3 and 0.91 before 0.91rc1 allows remote attackers to cause a denial of service (core dump) via a crafted RAR file with a modified vm_codesize value, which triggers a heap-based buffer overflow.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ClamAV RAR处理远程堆溢出拒绝服务漏洞
Vulnerability Description
Clam AntiVirus是Unix的GPL杀毒工具包,很多邮件网关产品都在使用。 ClamAV的libclamav库中的unrar.c文件在扫描特制的RAR压缩文件时存在堆溢出漏洞,如果用户受骗访问了设置有特制vm_codesize值的RAR文件的话,就可能触发这个溢出。但由于溢出的内容是用户不可控的,因此这个漏洞只能导致core dump。
CVSS Information
N/A
Vulnerability Type
N/A