CVE-2011-2721
ClamAV < 0.97.2 - Denial of Service via Hash Calculation Off-by-One Error
Title source: llmDescription
Off-by-one error in the cli_hm_scan function in matcher-hash.c in libclamav in ClamAV before 0.97.2 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message that is not properly handled during certain hash calculations.
References (18)
Core 18
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/68785
Patch x_refsource_confirm
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2818
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/45382
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-November/068942.html
Various Sources x_refsource_confirm
http://git.clamav.net/gitweb?p=clamav-devel.git%3Ba=blob_plain%3Bf=ChangeLog%3Bhb=clamav-0.97.2
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1025858
Patch x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=725694
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1179-1
Patch x_refsource_confirm
https://bugzilla.novell.com/show_bug.cgi?id=708263
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/46717
Patch mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/07/26/3
Various Sources x_refsource_confirm
http://git.clamav.net/gitweb?p=clamav-devel.git%3Ba=commit%3Bh=4842733eb3f09be61caeed83778bb6679141dbc5
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-November/068940.html
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-November/068941.html
Patch mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/07/26/13
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/48891
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/74181
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2011:122
Scores
EPSS
0.0338
EPSS Percentile
87.5%
Details
CWE
CWE-189
Status
published
Products (42)
clamav/clamav
0.01
clamav/clamav
0.02
clamav/clamav
0.3
clamav/clamav
0.03
clamav/clamav
0.05
clamav/clamav
0.8 rc3
clamav/clamav
0.9 rc1
clamav/clamav
0.10
clamav/clamav
0.12
clamav/clamav
0.13
... and 32 more
Published
Aug 05, 2011
Tracked Since
Feb 18, 2026