CVE-2008-1389

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
04/09/2008
Last modified:
09/04/2025

Description

libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote attackers to cause a denial of service (application crash) via a malformed CHM file, related to an "invalid memory access."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:* 0.93.3 (including)
cpe:2.3:a:clam_anti-virus:clamav:0.11:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.12:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.13:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.14:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.14:pre:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.15:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.20:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.21:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.22:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.23:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.24:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.51:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.52:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.53:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools