Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2007-4510

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2007-4510
Last Modified 07 Mar 2011 09:58:41
Published 23 Aug 2007 03:17:00
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2007-4510

Summary

ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other products, allows remote attackers to cause a denial of service (application crash) via (1) a crafted RTF file, which triggers a NULL dereference in the cli_scanrtf function in libclamav/rtf.c; or (2) a crafted HTML document with a data: URI, which triggers a NULL dereference in the cli_html_normalise function in libclamav/htmlnorm.c. NOTE: some of these details are obtained from third party information.

Vulnerable Systems

Application

  • Clam Anti-virus Clamav 0.91.2

  • Kolab Server 2.0

  • Kolab Server 2.0.1

  • Kolab Server 2.0.2

  • Kolab Server 2.0.3

  • Kolab Server 2.0.4

  • Kolab Server 2.1

  • Kolab Server 2.2beta1


References

BID - 25398

SECUNIA - 26552

SECUNIA - 26530

CONFIRM - https://wwws.clamav.net/bugzilla/show_bug.cgi?id=611

CONFIRM - https://wwws.clamav.net/bugzilla/show_bug.cgi?id=582

XF - clamav-clihtmlnormalise-dos(36177)

XF - clamav-rtf-dos(36173)

VUPEN - ADV-2008-0924

VUPEN - ADV-2007-2952

CONFIRM - http://sourceforge.net/project/shownotes.php?release_id=533658

CONFIRM - http://kolab.org/security/kolab-vendor-notice-17.txt

FEDORA - FEDORA-2007-2050

TRUSTIX - 2007-0026

SUSE - SUSE-SR:2007:018

MANDRIVA - MDKSA-2007:172

DEBIAN - DSA-1366

SREASON - 3054

GENTOO - GLSA-200709-14

SECUNIA - 29420

SECUNIA - 26916

SECUNIA - 26822

SECUNIA - 26751

SECUNIA - 26683

SECUNIA - 26674

SECUNIA - 26654

APPLE - APPLE-SA-2008-03-18

CONFIRM - http://docs.info.apple.com/article.html?artnum=307562

Related Patches

Apple 2008-03-18 Security Update 2008-002 v1.0 Client (Leopard)

Apple 2008-03-26 Security Update 2008-002 v1.1 Server (Leopard) (Rev 2)

Apple 2008-03-26 Security Update 2008-002 v1.1 Client (Leopard) (Rev 2)


Last Updated: 27 May 2016 10:45:53