CVE-2007-6029
Unspecified vulnerability in ClamAV 0.91.1 and 0.91.2 allows remote attackers to execute arbitrary code via a crafted e-mail message.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in ClamAV 0.91.1 and 0.91.2 allows remote attackers to execute arbitrary code via a crafted e-mail message. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.59% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- clam anti-virus/clamav
- Source
- cve@mitre.org
References
- http://wabisabilabi.blogspot.com/2007/11/focus-on-clamav-remote-code-execution.html
- http://wslabi.com/wabisabilabi/showBidInfo.do?code=ZD-00000069
- http://www.securityfocus.com/bid/26463
- http://wabisabilabi.blogspot.com/2007/11/focus-on-clamav-remote-code-execution.html
- http://wslabi.com/wabisabilabi/showBidInfo.do?code=ZD-00000069
- http://www.securityfocus.com/bid/26463
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.