fkie_cve-2008-5314
Vulnerability from fkie_nvd
Published
2008-12-03 17:30
Modified
2025-04-09 00:30
Severity ?
Summary
Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted JPEG file, related to the cli_check_jpeg_exploit, jpeg_check_photoshop, and jpeg_check_photoshop_8bim functions.
References
Impacted products
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:*", "matchCriteriaId": "EC7AF1DF-A5B0-4A28-8039-8195135DC02B", "versionEndIncluding": "0.94.1", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.70:*:*:*:*:*:*:*", "matchCriteriaId": "508C140C-2F87-4270-85B0-00EA6678A344", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.71:*:*:*:*:*:*:*", "matchCriteriaId": "3033A4A2-47E9-434F-BA0A-0F2476A67899", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.72:*:*:*:*:*:*:*", "matchCriteriaId": "4680089D-DEFB-41E3-AFAF-6DA9252F2DCD", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.73:*:*:*:*:*:*:*", "matchCriteriaId": "307ED99C-32B8-4C0C-8C55-E2BA6EDB961F", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.74:*:*:*:*:*:*:*", "matchCriteriaId": "DEF4F0DE-DC05-4F06-BC2D-09BAEAB25184", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.75:*:*:*:*:*:*:*", "matchCriteriaId": "0C1EDFB4-B0C8-4832-BCA1-C35D28877581", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.75.1:*:*:*:*:*:*:*", "matchCriteriaId": "BF60319C-CFFB-47F4-BDCB-90A5D0FB4240", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.80:*:*:*:*:*:*:*", "matchCriteriaId": "4EF47B2A-4520-4872-987D-2EF88344ADB2", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.80:rc:*:*:*:*:*:*", "matchCriteriaId": "5909491A-3D43-4648-B0F9-983BF2BE13B4", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.80:rc2:*:*:*:*:*:*", "matchCriteriaId": "3DB0BD14-60D1-4482-A91E-AFA501DE1F14", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.80:rc3:*:*:*:*:*:*", "matchCriteriaId": "FFFDE6BB-38A1-4074-A3E1-E59BB5E7ED74", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.80:rc4:*:*:*:*:*:*", "matchCriteriaId": "79FC2D39-6F8E-4267-8D4B-0C59D28A0E27", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.81:*:*:*:*:*:*:*", "matchCriteriaId": "FC31E071-6BB8-45FE-AA09-E7E459B549D2", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.81:rc1:*:*:*:*:*:*", "matchCriteriaId": "89533C50-275D-440D-88B4-363B3DED39E4", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.82:*:*:*:*:*:*:*", "matchCriteriaId": "53D884A1-305C-416A-9851-3A7D875FDC47", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.83:*:*:*:*:*:*:*", "matchCriteriaId": "E58A6CBC-ED1C-430D-8F43-88694971A850", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.84:*:*:*:*:*:*:*", "matchCriteriaId": "E330A535-A376-4BFF-BB1B-31E83370FC02", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.84:rc1:*:*:*:*:*:*", "matchCriteriaId": "E787E42E-3339-47FD-904E-5E3C73991CA9", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.84:rc2:*:*:*:*:*:*", "matchCriteriaId": "F21E03C7-0293-402C-ACAE-41E7F11B7AF2", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.85:*:*:*:*:*:*:*", "matchCriteriaId": "EDF94B1E-E8D4-4952-9081-1254F335445D", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.85.1:*:*:*:*:*:*:*", "matchCriteriaId": "8657268E-4C78-4565-9966-7329095A7905", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.86:*:*:*:*:*:*:*", "matchCriteriaId": "8D20F0D5-2291-4F24-94DB-180CDF926B93", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.86:rc1:*:*:*:*:*:*", "matchCriteriaId": "B8BD1ADF-C784-4E43-A6A5-09D416E96AE4", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.86.1:*:*:*:*:*:*:*", "matchCriteriaId": "A0E2884A-615F-4063-8FB7-EC157C3EC07F", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.86.2:*:*:*:*:*:*:*", "matchCriteriaId": "D7BC41B7-272F-44BB-BD48-6C9231402526", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.87:*:*:*:*:*:*:*", "matchCriteriaId": "D23F1D35-6073-49B0-8DD4-C58AEE2CC83C", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.87.1:*:*:*:*:*:*:*", "matchCriteriaId": "D87DA1D8-59AC-4372-BBFC-ED8BC6603AAC", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.88:*:*:*:*:*:*:*", "matchCriteriaId": "5F56722F-F61A-404B-B0B2-1C92C22D0436", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.88.1:*:*:*:*:*:*:*", "matchCriteriaId": "D00EBC44-B4AB-443F-A063-8C8CB64F5F94", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.88.2:*:*:*:*:*:*:*", "matchCriteriaId": "FFFA6F1E-9F25-400C-B626-3B9EDA396913", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.88.3:*:*:*:*:*:*:*", "matchCriteriaId": "2DB68680-FA6D-4235-90DA-E3DF0E5BB666", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.88.4:*:*:*:*:*:*:*", "matchCriteriaId": "0E5BCBA5-0CE1-4112-8C3D-BAED9C5537B9", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.88.5:*:*:*:*:*:*:*", "matchCriteriaId": "3908B34C-823E-47BA-8A64-23547D2AB027", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.88.6:*:*:*:*:*:*:*", "matchCriteriaId": "557C5437-4B40-4E89-A23D-96B95829281D", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.88.7:*:*:*:*:*:*:*", "matchCriteriaId": "A3394AD1-C667-46E7-82D3-E2E381CCC9FA", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.90:*:*:*:*:*:*:*", "matchCriteriaId": "142588F8-15C3-4288-BE7C-B2F7447BD60F", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.90.1:*:*:*:*:*:*:*", "matchCriteriaId": "EC18418B-7477-436C-A24A-081701968DEF", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.90.2:*:*:*:*:*:*:*", "matchCriteriaId": "1A85C689-95E0-41F7-83D9-5A8B0AB42390", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.90.3:*:*:*:*:*:*:*", "matchCriteriaId": "BC24A055-278C-4A78-8C68-AC7618EF3EF5", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.91:*:*:*:*:*:*:*", "matchCriteriaId": "CC992A3B-24B4-48D8-BFBF-9B7884D11D28", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.91.1:*:*:*:*:*:*:*", "matchCriteriaId": "8EFAC7BA-2A39-46A8-BF91-5537532F45D2", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.91.2:*:*:*:*:*:*:*", "matchCriteriaId": "733CB165-98CD-4F8E-8A6D-07CF522634BA", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.92:*:*:*:*:*:*:*", "matchCriteriaId": "8670A5ED-C41E-40B9-B2C9-68F22734B444", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.92.1:*:*:*:*:*:*:*", "matchCriteriaId": "C8BE6F91-5442-4156-B137-E4AD3E21CF88", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.93:*:*:*:*:*:*:*", "matchCriteriaId": "40F14DB9-8437-4CEB-9D63-098FD9E604E7", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.93.1:*:*:*:*:*:*:*", "matchCriteriaId": "A4C92175-5E97-4197-8495-25900134B652", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.93.3:*:*:*:*:*:*:*", "matchCriteriaId": "5CF50FEF-9840-4B6C-BC60-02956F9E3099", "vulnerable": true }, { "criteria": "cpe:2.3:a:clam_anti-virus:clamav:0.94:*:*:*:*:*:*:*", "matchCriteriaId": "67373928-C0E0-4A12-B97A-575EC57E5072", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted JPEG file, related to the cli_check_jpeg_exploit, jpeg_check_photoshop, and jpeg_check_photoshop_8bim functions." }, { "lang": "es", "value": "Vulnerabilidad de consumo de pila en el archivo libclamav/special.c en ClamAV y versiones anteriores 0.94.2, que permite a los atacantes remotos causar una denegaci\u00f3n de servicios (ca\u00edda de demonio) a trav\u00e9s de un archivo JPEG manipulado, relativo a las funciones cli_check_jpeg_exploit, jpeg_check_photoshop y jpeg_check_photoshop_8bim." } ], "id": "CVE-2008-5314", "lastModified": "2025-04-09T00:30:58.490", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 4.3, "confidentialityImpact": "NONE", "integrityImpact": "NONE", "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ] }, "published": "2008-12-03T17:30:00.477", "references": [ { "source": "cve@mitre.org", "url": "http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" }, { "source": "cve@mitre.org", "url": "http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00003.html" }, { "source": "cve@mitre.org", "url": "http://lurker.clamav.net/message/20081126.150241.55b1e092.en.html" }, { "source": "cve@mitre.org", "url": "http://osvdb.org/50363" }, { "source": "cve@mitre.org", "url": "http://secunia.com/advisories/32926" }, { "source": "cve@mitre.org", "url": "http://secunia.com/advisories/32936" }, { "source": "cve@mitre.org", "url": "http://secunia.com/advisories/33016" }, { "source": "cve@mitre.org", "url": "http://secunia.com/advisories/33195" }, { "source": "cve@mitre.org", "url": "http://secunia.com/advisories/33317" }, { "source": "cve@mitre.org", "url": "http://secunia.com/advisories/33937" }, { "source": "cve@mitre.org", "url": "http://security.gentoo.org/glsa/glsa-200812-21.xml" }, { "source": "cve@mitre.org", "url": "http://sourceforge.net/project/shownotes.php?group_id=86638\u0026release_id=643134" }, { "source": "cve@mitre.org", "url": "http://support.apple.com/kb/HT3438" }, { "source": "cve@mitre.org", "url": "http://www.debian.org/security/2008/dsa-1680" }, { "source": "cve@mitre.org", "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:239" }, { "source": "cve@mitre.org", "url": "http://www.openwall.com/lists/oss-security/2008/12/01/8" }, { "source": "cve@mitre.org", "url": "http://www.securityfocus.com/bid/32555" }, { "source": "cve@mitre.org", "url": "http://www.securitytracker.com/id?1021296" }, { "source": "cve@mitre.org", "url": "http://www.ubuntu.com/usn/usn-684-1" }, { "source": "cve@mitre.org", "url": "http://www.vupen.com/english/advisories/2008/3311" }, { "source": "cve@mitre.org", "url": "http://www.vupen.com/english/advisories/2009/0422" }, { "source": "cve@mitre.org", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46985" }, { "source": "cve@mitre.org", "url": "https://www.exploit-db.com/exploits/7330" }, { "source": "cve@mitre.org", "tags": [ "Exploit" ], "url": "https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1266" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00003.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://lurker.clamav.net/message/20081126.150241.55b1e092.en.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://osvdb.org/50363" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://secunia.com/advisories/32926" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://secunia.com/advisories/32936" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://secunia.com/advisories/33016" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://secunia.com/advisories/33195" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://secunia.com/advisories/33317" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://secunia.com/advisories/33937" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://security.gentoo.org/glsa/glsa-200812-21.xml" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://sourceforge.net/project/shownotes.php?group_id=86638\u0026release_id=643134" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://support.apple.com/kb/HT3438" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.debian.org/security/2008/dsa-1680" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:239" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.openwall.com/lists/oss-security/2008/12/01/8" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securityfocus.com/bid/32555" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securitytracker.com/id?1021296" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.ubuntu.com/usn/usn-684-1" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.vupen.com/english/advisories/2008/3311" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.vupen.com/english/advisories/2009/0422" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46985" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://www.exploit-db.com/exploits/7330" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Exploit" ], "url": "https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1266" } ], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Deferred", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-399" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…