CVE
- Id
- 25354
- CVE No.
- CVE-2007-1997
- Status
- Candidate
- Description
- Integer signedness error in the (1) cab_unstore and (2) cab_extract functions in libclamav/cab.c in Clam AntiVirus (ClamAV) before 0.90.2 allow remote attackers to execute arbitrary code via a crafted CHM file that contains a negative integer, which passes a signed comparison and leads to a stack-based buffer overflow.
- Phase
- Assigned (20070412)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 252826 | 25354 | CVE-2007-1997 | IDEFENSE:20070416 Clam AntiVirus ClamAV CAB File Unstore Buffer Overflow Vulnerability | View |
| 252827 | 25354 | CVE-2007-1997 | URL:http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=513 | View |
| 252828 | 25354 | CVE-2007-1997 | CONFIRM:http://sourceforge.net/project/shownotes.php?release_id=500765 | View |
| 252829 | 25354 | CVE-2007-1997 | CONFIRM:http://support.novell.com/techcenter/psdb/50a5cb718f20761dd7e0b6b4e0935c52.html | View |
| 252830 | 25354 | CVE-2007-1997 | CONFIRM:http://docs.info.apple.com/article.html?artnum=307562 | View |
| 252831 | 25354 | CVE-2007-1997 | APPLE:APPLE-SA-2008-03-18 | View |
| 252832 | 25354 | CVE-2007-1997 | URL:http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html | View |
| 252833 | 25354 | CVE-2007-1997 | DEBIAN:DSA-1281 | View |
| 252834 | 25354 | CVE-2007-1997 | URL:http://www.debian.org/security/2007/dsa-1281 | View |
| 252835 | 25354 | CVE-2007-1997 | GENTOO:GLSA-200704-21 | View |
| 252836 | 25354 | CVE-2007-1997 | URL:http://security.gentoo.org/glsa/glsa-200704-21.xml | View |
| 252837 | 25354 | CVE-2007-1997 | MANDRIVA:MDKSA-2007:098 | View |
| 252838 | 25354 | CVE-2007-1997 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2007:098 | View |
| 252839 | 25354 | CVE-2007-1997 | SUSE:SUSE-SA:2007:026 | View |
| 252840 | 25354 | CVE-2007-1997 | URL:http://www.novell.com/linux/security/advisories/2007_26_clamav.html | View |
| 252841 | 25354 | CVE-2007-1997 | TRUSTIX:2007-0013 | View |
| 252842 | 25354 | CVE-2007-1997 | URL:http://www.trustix.org/errata/2007/0013/ | View |
| 252843 | 25354 | CVE-2007-1997 | BID:23473 | View |
| 252844 | 25354 | CVE-2007-1997 | URL:http://www.securityfocus.com/bid/23473 | View |
| 252845 | 25354 | CVE-2007-1997 | VUPEN:ADV-2007-1378 | View |
| 252846 | 25354 | CVE-2007-1997 | URL:http://www.vupen.com/english/advisories/2007/1378 | View |
| 252847 | 25354 | CVE-2007-1997 | VUPEN:ADV-2008-0924 | View |
| 252848 | 25354 | CVE-2007-1997 | URL:http://www.vupen.com/english/advisories/2008/0924/references | View |
| 252849 | 25354 | CVE-2007-1997 | SECTRACK:1017921 | View |
| 252850 | 25354 | CVE-2007-1997 | URL:http://www.securitytracker.com/id?1017921 | View |
| 252851 | 25354 | CVE-2007-1997 | SECUNIA:24891 | View |
| 252852 | 25354 | CVE-2007-1997 | URL:http://secunia.com/advisories/24891 | View |
| 252853 | 25354 | CVE-2007-1997 | SECUNIA:24920 | View |
| 252854 | 25354 | CVE-2007-1997 | URL:http://secunia.com/advisories/24920 | View |
| 252855 | 25354 | CVE-2007-1997 | SECUNIA:24946 | View |
| 252856 | 25354 | CVE-2007-1997 | URL:http://secunia.com/advisories/24946 | View |
| 252857 | 25354 | CVE-2007-1997 | SECUNIA:24996 | View |
| 252858 | 25354 | CVE-2007-1997 | URL:http://secunia.com/advisories/24996 | View |
| 252859 | 25354 | CVE-2007-1997 | SECUNIA:25022 | View |
| 252860 | 25354 | CVE-2007-1997 | URL:http://secunia.com/advisories/25022 | View |
| 252861 | 25354 | CVE-2007-1997 | SECUNIA:25028 | View |
| 252862 | 25354 | CVE-2007-1997 | URL:http://secunia.com/advisories/25028 | View |
| 252863 | 25354 | CVE-2007-1997 | SECUNIA:25189 | View |
| 252864 | 25354 | CVE-2007-1997 | URL:http://secunia.com/advisories/25189 | View |
| 252865 | 25354 | CVE-2007-1997 | SECUNIA:29420 | View |
| 252866 | 25354 | CVE-2007-1997 | URL:http://secunia.com/advisories/29420 | View |
| 252867 | 25354 | CVE-2007-1997 | XF:clamav-cabunstore-cabextract-bo(33637) | View |
Related JVN
| Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 54989 | JVNDB-2007-003681 | Weatimages の index.php における PHP リモートファイルインクルージョンの脆弱性 | Weatimages の index.php には、weatimages.ini が無い場合、PHP リモートファイルインクルージョンの脆弱性が存在します。 | CVE-2007-1999 | 25354 | 7.5 | http://jvndb.jvn.jp/ja/contents/2007/JVNDB-2007-003681.html | View |