Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ClamAV ClamBC < 0.103.0-rc - 'ClamBC' Executable Regular Expression Error
Vulnerability Description
ClamAV versions prior to 0.103.0-rc contain a vulnerability in function name processing through the ClamBC bytecode interpreter that allows attackers to manipulate bytecode function names. Attackers can exploit the weak input validation in function name encoding to potentially execute malicious bytecode or cause unexpected behavior in the ClamAV engine.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
N/A
Vulnerability Title
Cisco ClamAV ClamBC 代码注入漏洞
Vulnerability Description
Cisco ClamAV ClamBC是美国思科(Cisco)公司的一个字节码签名系统。 Cisco ClamAV ClamBC存在代码注入漏洞,该漏洞源于函数名处理存在弱输入验证,可能导致攻击者执行恶意字节码或引发意外行为。
CVSS Information
N/A
Vulnerability Type
N/A