Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Off-by-one error in the get_unicode_name function (libclamav/vba_extract.c) in Clam Anti-Virus (ClamAV) before 0.94.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted VBA project file, which triggers a heap-based buffer overflow.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ClamAV ’get_unicode_name‘函数单字节堆溢出漏洞
Vulnerability Description
Clam AntiVirus是Unix的GPL杀毒工具包,很多邮件网关产品都在使用。 Clam Anti-Virus (ClamAV)的get_unicode_name函数存在单字节堆溢出漏洞。远程攻击者可以利用一个特制的VBA工程文件,触发堆缓冲区溢出,从而造成拒绝服务(崩溃)或可能执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A