CVE-2005-2450 Affecting clamav package, versions <0.86.2-1


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
3.88% (89th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ECHOLATEST-CLAMAV-18599965
  • published9 Aug 2026
  • disclosed3 Aug 2005

Introduced: 3 Aug 2005

CVE-2005-2450  (opens in a new tab)

How to fix?

Upgrade Echo:latest clamav to version 0.86.2-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream clamav package and not the clamav package as distributed by Echo. See How to fix? for Echo:latest relevant fixed versions and status.

Multiple integer overflows in the (1) TNEF, (2) CHM, or (3) FSG file format processors in libclamav for Clam AntiVirus (ClamAV) 0.86.1 and earlier allow remote attackers to gain privileges via a crafted e-mail message.

CVSS Base Scores

version 3.1