CVE-2013-6497
Mandriva Linux Security Advisory 2014-217
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
clamscan in ClamAV before 0.98.5, when using -a option, allows remote attackers to cause a denial of service (crash) as demonstrated by the jwplayer.js file.
clamscan en ClamAV anterior a 0.98.5, cuando utiliza la opción -a, permite a atacantes remotos causar una denegación de servicio (caída) como fue demostrado por el fichero jwplayer.js.
Kurt Seifried discovered that ClamAV incorrectly handled certain JavaScript files. An attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service, or possibly execute arbitrary code. Damien Millescamp discovered that ClamAV incorrectly handled certain PE files. An attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service, or possibly execute arbitrary code. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-11-04 CVE Reserved
- 2014-11-20 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-17: DEPRECATED: Code
CAPEC
References (17)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/59645 | Third Party Advisory | |
http://secunia.com/advisories/60150 | Third Party Advisory | |
http://www.openwall.com/lists/oss-security/2014/11/19/2 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2014/11/19/5 | Mailing List |
|
http://www.securityfocus.com/bid/71178 | Vdb Entry | |
https://bugzilla.redhat.com/show_bug.cgi?id=1138101 | X_refsource_confirm | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/98804 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://blog.clamav.net/2014/11/clamav-0985-has-been-released.html | 2017-08-29 |