clamav

Page content
  • Author: vmiklos
  • Vulnerable: 0.90.2-1terminus2
  • Unaffected: 0.90.2-1terminus3

Metaeye SG has reported a vulnerability in ClamAV, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to a NULL-pointer dereference error within libclamav/unrar/unrarvm.c when handling RAR archives and can be exploited to cause a crash via a specially crafted RAR archive.

CVEs: