CVE-2007-3122 Affecting clamav package, versions [,0.90.3)[0.0,0.91)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
54.19% (98th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-CLAMAV-2381140
  • published26 Jan 2022
  • disclosed7 Jun 2007
  • creditUnknown

Introduced: 7 Jun 2007

CVE-2007-3122  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade clamav to version 0.90.3, 0.91 or higher.

Overview

The parsing engine in ClamAV before 0.90.3 and 0.91 before 0.91rc1 allows remote attackers to bypass scanning via a RAR file with a header flag value of 10, which can be processed by WinRAR.

CVSS Scores

version 3.1