CVE-2008-5050

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
13/11/2008
Last modified:
09/04/2025

Description

Off-by-one error in the get_unicode_name function (libclamav/vba_extract.c) in Clam Anti-Virus (ClamAV) before 0.94.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted VBA project file, which triggers a heap-based buffer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:* 0.94 (including)
cpe:2.3:a:clam_anti-virus:clamav:0.01:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.02:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.03:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.04:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.05:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.06:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.10:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.11:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.12:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.13:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.14:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.14:pre:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.15:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.20:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools