CVE
- Id
- 25354
- CVE No.
- CVE-2007-1997
- Status
- Candidate
- Description
- Integer signedness error in the (1) cab_unstore and (2) cab_extract functions in libclamav/cab.c in Clam AntiVirus (ClamAV) before 0.90.2 allow remote attackers to execute arbitrary code via a crafted CHM file that contains a negative integer, which passes a signed comparison and leads to a stack-based buffer overflow.
- Phase
- Assigned (20070412)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
252826 | 25354 | CVE-2007-1997 | IDEFENSE:20070416 Clam AntiVirus ClamAV CAB File Unstore Buffer Overflow Vulnerability | View |
252827 | 25354 | CVE-2007-1997 | URL:http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=513 | View |
252828 | 25354 | CVE-2007-1997 | CONFIRM:http://sourceforge.net/project/shownotes.php?release_id=500765 | View |
252829 | 25354 | CVE-2007-1997 | CONFIRM:http://support.novell.com/techcenter/psdb/50a5cb718f20761dd7e0b6b4e0935c52.html | View |
252830 | 25354 | CVE-2007-1997 | CONFIRM:http://docs.info.apple.com/article.html?artnum=307562 | View |
252831 | 25354 | CVE-2007-1997 | APPLE:APPLE-SA-2008-03-18 | View |
252832 | 25354 | CVE-2007-1997 | URL:http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html | View |
252833 | 25354 | CVE-2007-1997 | DEBIAN:DSA-1281 | View |
252834 | 25354 | CVE-2007-1997 | URL:http://www.debian.org/security/2007/dsa-1281 | View |
252835 | 25354 | CVE-2007-1997 | GENTOO:GLSA-200704-21 | View |
252836 | 25354 | CVE-2007-1997 | URL:http://security.gentoo.org/glsa/glsa-200704-21.xml | View |
252837 | 25354 | CVE-2007-1997 | MANDRIVA:MDKSA-2007:098 | View |
252838 | 25354 | CVE-2007-1997 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2007:098 | View |
252839 | 25354 | CVE-2007-1997 | SUSE:SUSE-SA:2007:026 | View |
252840 | 25354 | CVE-2007-1997 | URL:http://www.novell.com/linux/security/advisories/2007_26_clamav.html | View |
252841 | 25354 | CVE-2007-1997 | TRUSTIX:2007-0013 | View |
252842 | 25354 | CVE-2007-1997 | URL:http://www.trustix.org/errata/2007/0013/ | View |
252843 | 25354 | CVE-2007-1997 | BID:23473 | View |
252844 | 25354 | CVE-2007-1997 | URL:http://www.securityfocus.com/bid/23473 | View |
252845 | 25354 | CVE-2007-1997 | VUPEN:ADV-2007-1378 | View |
252846 | 25354 | CVE-2007-1997 | URL:http://www.vupen.com/english/advisories/2007/1378 | View |
252847 | 25354 | CVE-2007-1997 | VUPEN:ADV-2008-0924 | View |
252848 | 25354 | CVE-2007-1997 | URL:http://www.vupen.com/english/advisories/2008/0924/references | View |
252849 | 25354 | CVE-2007-1997 | SECTRACK:1017921 | View |
252850 | 25354 | CVE-2007-1997 | URL:http://www.securitytracker.com/id?1017921 | View |
252851 | 25354 | CVE-2007-1997 | SECUNIA:24891 | View |
252852 | 25354 | CVE-2007-1997 | URL:http://secunia.com/advisories/24891 | View |
252853 | 25354 | CVE-2007-1997 | SECUNIA:24920 | View |
252854 | 25354 | CVE-2007-1997 | URL:http://secunia.com/advisories/24920 | View |
252855 | 25354 | CVE-2007-1997 | SECUNIA:24946 | View |
252856 | 25354 | CVE-2007-1997 | URL:http://secunia.com/advisories/24946 | View |
252857 | 25354 | CVE-2007-1997 | SECUNIA:24996 | View |
252858 | 25354 | CVE-2007-1997 | URL:http://secunia.com/advisories/24996 | View |
252859 | 25354 | CVE-2007-1997 | SECUNIA:25022 | View |
252860 | 25354 | CVE-2007-1997 | URL:http://secunia.com/advisories/25022 | View |
252861 | 25354 | CVE-2007-1997 | SECUNIA:25028 | View |
252862 | 25354 | CVE-2007-1997 | URL:http://secunia.com/advisories/25028 | View |
252863 | 25354 | CVE-2007-1997 | SECUNIA:25189 | View |
252864 | 25354 | CVE-2007-1997 | URL:http://secunia.com/advisories/25189 | View |
252865 | 25354 | CVE-2007-1997 | SECUNIA:29420 | View |
252866 | 25354 | CVE-2007-1997 | URL:http://secunia.com/advisories/29420 | View |
252867 | 25354 | CVE-2007-1997 | XF:clamav-cabunstore-cabextract-bo(33637) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
54989 | JVNDB-2007-003681 | Weatimages の index.php における PHP リモートファイルインクルージョンの脆弱性 | Weatimages の index.php には、weatimages.ini が無い場合、PHP リモートファイルインクルージョンの脆弱性が存在します。 | CVE-2007-1999 | 25354 | 7.5 | http://jvndb.jvn.jp/ja/contents/2007/JVNDB-2007-003681.html | View |