CVE-2007-3123

Publication date 7 June 2007

Last updated 24 July 2024


Ubuntu priority

unrar.c in libclamav in ClamAV before 0.90.3 and 0.91 before 0.91rc1 allows remote attackers to cause a denial of service (core dump) via a crafted RAR file with a modified vm_codesize value, which triggers a heap-based buffer overflow.

Status

Package Ubuntu Release Status
clamav 8.04 LTS hardy
Fixed 0.90.3-1
7.10 gutsy
Fixed 0.90.3-1
7.04 feisty
Fixed 0.90.2-0ubuntu1.3
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper
Fixed 0.92.1~dfsg2-1.1~dapper2