Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2004-1876

Overview

Vulnerability Score 4.6 4.6
CVE Id CVE-2004-1876
Last Modified 05 Sep 2008 04:42:35
Published 30 Mar 2004 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2004-1876

Summary

The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name.

Vulnerable Systems

Application

  • Clam Anti-virus Clamav 0.51

  • Clam Anti-virus Clamav 0.52

  • Clam Anti-virus Clamav 0.53

  • Clam Anti-virus Clamav 0.54

  • Clam Anti-virus Clamav 0.60

  • Clam Anti-virus Clamav 0.65

  • Clam Anti-virus Clamav 0.67

  • Clam Anti-virus Clamav 0.68

  • Clam Anti-virus Clamav 0.68.1


References

XF - clamantivirus-virusevent-gain-privileges(15692)

BID - 10007

GENTOO - GLSA-200405-03

SECUNIA - 11253

BUGTRAQ - 20040330 clamd - NEVER use "%f" in your "VirusEvent"


Last Updated: 27 May 2016 10:39:13