CVE-2013-2020
Apple Security Advisory 2013-09-12-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an out-of-bounds read.
Desbordamiento de entero en la función cli_scanpe en pe.c en ClamAV anterior a v0.97.8 permite a atacantes remotos provocar una denegación de servicio (caída de la aplicación) a través de un desplazamiento mayor que el tamaño de las secciones PE en un paquete ejecutable UPX, que dispara un error de salida de rango en la lectura.
Multiple vulnerabilities have been found in ClamAV, the worst of which could lead to arbitrary code execution. Versions less than 0.98 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-02-19 CVE Reserved
- 2013-05-13 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-189: Numeric Errors
CAPEC
References (21)
URL | Tag | Source |
---|---|---|
http://support.apple.com/kb/HT5880 | X_refsource_confirm |
|
http://support.apple.com/kb/HT5892 | X_refsource_confirm |
|
http://www.openwall.com/lists/oss-security/2013/04/25/2 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2013/04/29/20 | Mailing List |
|
http://www.securityfocus.com/bid/59434 | Vdb Entry | |
https://bugzilla.clamav.net/show_bug.cgi?id=7055 | X_refsource_confirm | |
https://github.com/vrtadmin/clamav-devel/commit/270e368b99e93aa5447d46c797c92c3f9f39f375 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://blog.clamav.net/2013/04/clamav-0978-has-been-released.html | 2015-09-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 10.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "10.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 11.10 Search vendor "Canonical" for product "Ubuntu Linux" and version "11.10" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 12.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "12.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 12.10 Search vendor "Canonical" for product "Ubuntu Linux" and version "12.10" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 13.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "13.04" | - |
Affected
| ||||||
Suse Search vendor "Suse" | Linux Enterprise Server Search vendor "Suse" for product "Linux Enterprise Server" | 11.0 Search vendor "Suse" for product "Linux Enterprise Server" and version "11.0" | sp1 |
Affected
| ||||||
Suse Search vendor "Suse" | Linux Enterprise Server Search vendor "Suse" for product "Linux Enterprise Server" | 11.0 Search vendor "Suse" for product "Linux Enterprise Server" and version "11.0" | sp2 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | <= 0.97.7 Search vendor "Clamav" for product "Clamav" and version " <= 0.97.7" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.9 Search vendor "Clamav" for product "Clamav" and version "0.9" | rc1 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90 Search vendor "Clamav" for product "Clamav" and version "0.90" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90 Search vendor "Clamav" for product "Clamav" and version "0.90" | rc1 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90 Search vendor "Clamav" for product "Clamav" and version "0.90" | rc1.1 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90 Search vendor "Clamav" for product "Clamav" and version "0.90" | rc2 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90 Search vendor "Clamav" for product "Clamav" and version "0.90" | rc3 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90.1 Search vendor "Clamav" for product "Clamav" and version "0.90.1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90.1_p0 Search vendor "Clamav" for product "Clamav" and version "0.90.1_p0" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90.2 Search vendor "Clamav" for product "Clamav" and version "0.90.2" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90.2_p0 Search vendor "Clamav" for product "Clamav" and version "0.90.2_p0" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90.3 Search vendor "Clamav" for product "Clamav" and version "0.90.3" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90.3_p0 Search vendor "Clamav" for product "Clamav" and version "0.90.3_p0" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90.3_p1 Search vendor "Clamav" for product "Clamav" and version "0.90.3_p1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.91 Search vendor "Clamav" for product "Clamav" and version "0.91" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.91 Search vendor "Clamav" for product "Clamav" and version "0.91" | rc1 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.91 Search vendor "Clamav" for product "Clamav" and version "0.91" | rc2 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.91.1 Search vendor "Clamav" for product "Clamav" and version "0.91.1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.91.2 Search vendor "Clamav" for product "Clamav" and version "0.91.2" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.91.2_p0 Search vendor "Clamav" for product "Clamav" and version "0.91.2_p0" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.92 Search vendor "Clamav" for product "Clamav" and version "0.92" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.92.1 Search vendor "Clamav" for product "Clamav" and version "0.92.1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.92_p0 Search vendor "Clamav" for product "Clamav" and version "0.92_p0" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.93 Search vendor "Clamav" for product "Clamav" and version "0.93" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.93.1 Search vendor "Clamav" for product "Clamav" and version "0.93.1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.93.2 Search vendor "Clamav" for product "Clamav" and version "0.93.2" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.93.3 Search vendor "Clamav" for product "Clamav" and version "0.93.3" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.94 Search vendor "Clamav" for product "Clamav" and version "0.94" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.94.1 Search vendor "Clamav" for product "Clamav" and version "0.94.1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.94.2 Search vendor "Clamav" for product "Clamav" and version "0.94.2" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.95 Search vendor "Clamav" for product "Clamav" and version "0.95" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.95 Search vendor "Clamav" for product "Clamav" and version "0.95" | rc1 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.95 Search vendor "Clamav" for product "Clamav" and version "0.95" | rc2 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.95 Search vendor "Clamav" for product "Clamav" and version "0.95" | src1 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.95 Search vendor "Clamav" for product "Clamav" and version "0.95" | src2 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.95.1 Search vendor "Clamav" for product "Clamav" and version "0.95.1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.95.2 Search vendor "Clamav" for product "Clamav" and version "0.95.2" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.95.3 Search vendor "Clamav" for product "Clamav" and version "0.95.3" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.96 Search vendor "Clamav" for product "Clamav" and version "0.96" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.96 Search vendor "Clamav" for product "Clamav" and version "0.96" | rc1 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.96 Search vendor "Clamav" for product "Clamav" and version "0.96" | rc2 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.96.1 Search vendor "Clamav" for product "Clamav" and version "0.96.1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.96.2 Search vendor "Clamav" for product "Clamav" and version "0.96.2" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.96.3 Search vendor "Clamav" for product "Clamav" and version "0.96.3" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.96.4 Search vendor "Clamav" for product "Clamav" and version "0.96.4" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.96.5 Search vendor "Clamav" for product "Clamav" and version "0.96.5" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.97 Search vendor "Clamav" for product "Clamav" and version "0.97" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.97 Search vendor "Clamav" for product "Clamav" and version "0.97" | rc |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.97.1 Search vendor "Clamav" for product "Clamav" and version "0.97.1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.97.2 Search vendor "Clamav" for product "Clamav" and version "0.97.2" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.97.3 Search vendor "Clamav" for product "Clamav" and version "0.97.3" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.97.4 Search vendor "Clamav" for product "Clamav" and version "0.97.4" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.97.5 Search vendor "Clamav" for product "Clamav" and version "0.97.5" | - |
Affected
|