CVE-2014-9050
Gentoo Linux Security Advisory 201412-05
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Heap-based buffer overflow in the cli_scanpe function in libclamav/pe.c in ClamAV before 0.98.5 allows remote attackers to cause a denial of service (crash) via a crafted y0da Crypter PE file.
El desbordamiento de búfer en la región heap de la memoria en la función cli_scanpe en el archivo libclamav/pe.c en ClamAV anterior a versión 0.98.5, permite a los atacantes remotos causar una denegación de servicio (bloqueo) por medio de un archivo y0da Crypter PE diseñado.
Kurt Seifried discovered that ClamAV incorrectly handled certain JavaScript files. An attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service, or possibly execute arbitrary code. Damien Millescamp discovered that ClamAV incorrectly handled certain PE files. An attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service, or possibly execute arbitrary code. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-11-21 CVE Reserved
- 2014-11-27 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/59645 | Third Party Advisory | |
http://secunia.com/advisories/62542 | Third Party Advisory | |
http://www.openwall.com/lists/oss-security/2014/11/22/1 | Mailing List |
|
http://www.securityfocus.com/bid/71242 | Vdb Entry | |
http://www.securitytracker.com/id/1031268 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://github.com/vrtadmin/clamav-devel/commit/fc3794a54d2affe5770c1f876484a871c783e91e | 2024-08-06 |
URL | Date | SRC |
---|---|---|
http://www.ubuntu.com/usn/USN-2423-1 | 2015-04-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | <= 0.94.3 Search vendor "Clamav" for product "Clamav" and version " <= 0.94.3" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.01 Search vendor "Clamav" for product "Clamav" and version "0.01" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.02 Search vendor "Clamav" for product "Clamav" and version "0.02" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.3 Search vendor "Clamav" for product "Clamav" and version "0.3" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.03 Search vendor "Clamav" for product "Clamav" and version "0.03" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.05 Search vendor "Clamav" for product "Clamav" and version "0.05" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.8 Search vendor "Clamav" for product "Clamav" and version "0.8" | rc3 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.9 Search vendor "Clamav" for product "Clamav" and version "0.9" | rc1 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.10 Search vendor "Clamav" for product "Clamav" and version "0.10" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.12 Search vendor "Clamav" for product "Clamav" and version "0.12" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.13 Search vendor "Clamav" for product "Clamav" and version "0.13" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.14 Search vendor "Clamav" for product "Clamav" and version "0.14" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.14 Search vendor "Clamav" for product "Clamav" and version "0.14" | pre |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.15 Search vendor "Clamav" for product "Clamav" and version "0.15" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.20 Search vendor "Clamav" for product "Clamav" and version "0.20" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.21 Search vendor "Clamav" for product "Clamav" and version "0.21" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.22 Search vendor "Clamav" for product "Clamav" and version "0.22" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.23 Search vendor "Clamav" for product "Clamav" and version "0.23" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.24 Search vendor "Clamav" for product "Clamav" and version "0.24" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.51 Search vendor "Clamav" for product "Clamav" and version "0.51" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.52 Search vendor "Clamav" for product "Clamav" and version "0.52" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.53 Search vendor "Clamav" for product "Clamav" and version "0.53" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.54 Search vendor "Clamav" for product "Clamav" and version "0.54" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.60 Search vendor "Clamav" for product "Clamav" and version "0.60" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.60p Search vendor "Clamav" for product "Clamav" and version "0.60p" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.65 Search vendor "Clamav" for product "Clamav" and version "0.65" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.66 Search vendor "Clamav" for product "Clamav" and version "0.66" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.67 Search vendor "Clamav" for product "Clamav" and version "0.67" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.67-1 Search vendor "Clamav" for product "Clamav" and version "0.67-1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.68 Search vendor "Clamav" for product "Clamav" and version "0.68" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.68.1 Search vendor "Clamav" for product "Clamav" and version "0.68.1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.70 Search vendor "Clamav" for product "Clamav" and version "0.70" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.70 Search vendor "Clamav" for product "Clamav" and version "0.70" | rc |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.71 Search vendor "Clamav" for product "Clamav" and version "0.71" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.72 Search vendor "Clamav" for product "Clamav" and version "0.72" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.73 Search vendor "Clamav" for product "Clamav" and version "0.73" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.74 Search vendor "Clamav" for product "Clamav" and version "0.74" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.75 Search vendor "Clamav" for product "Clamav" and version "0.75" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.75.1 Search vendor "Clamav" for product "Clamav" and version "0.75.1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.80 Search vendor "Clamav" for product "Clamav" and version "0.80" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.80 Search vendor "Clamav" for product "Clamav" and version "0.80" | rc |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.80 Search vendor "Clamav" for product "Clamav" and version "0.80" | rc1 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.80 Search vendor "Clamav" for product "Clamav" and version "0.80" | rc2 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.80 Search vendor "Clamav" for product "Clamav" and version "0.80" | rc3 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.80 Search vendor "Clamav" for product "Clamav" and version "0.80" | rc4 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.80_rc Search vendor "Clamav" for product "Clamav" and version "0.80_rc" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.81 Search vendor "Clamav" for product "Clamav" and version "0.81" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.81 Search vendor "Clamav" for product "Clamav" and version "0.81" | rc1 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.82 Search vendor "Clamav" for product "Clamav" and version "0.82" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.83 Search vendor "Clamav" for product "Clamav" and version "0.83" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.84 Search vendor "Clamav" for product "Clamav" and version "0.84" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.84 Search vendor "Clamav" for product "Clamav" and version "0.84" | rc1 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.84 Search vendor "Clamav" for product "Clamav" and version "0.84" | rc2 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.85 Search vendor "Clamav" for product "Clamav" and version "0.85" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.85.1 Search vendor "Clamav" for product "Clamav" and version "0.85.1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.86 Search vendor "Clamav" for product "Clamav" and version "0.86" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.86 Search vendor "Clamav" for product "Clamav" and version "0.86" | rc1 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.86.1 Search vendor "Clamav" for product "Clamav" and version "0.86.1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.86.2 Search vendor "Clamav" for product "Clamav" and version "0.86.2" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.87 Search vendor "Clamav" for product "Clamav" and version "0.87" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.87.1 Search vendor "Clamav" for product "Clamav" and version "0.87.1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.88 Search vendor "Clamav" for product "Clamav" and version "0.88" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.88.1 Search vendor "Clamav" for product "Clamav" and version "0.88.1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.88.2 Search vendor "Clamav" for product "Clamav" and version "0.88.2" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.88.3 Search vendor "Clamav" for product "Clamav" and version "0.88.3" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.88.4 Search vendor "Clamav" for product "Clamav" and version "0.88.4" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.88.5 Search vendor "Clamav" for product "Clamav" and version "0.88.5" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.88.6 Search vendor "Clamav" for product "Clamav" and version "0.88.6" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.88.7 Search vendor "Clamav" for product "Clamav" and version "0.88.7" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.88.7_p0 Search vendor "Clamav" for product "Clamav" and version "0.88.7_p0" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.88.7_p1 Search vendor "Clamav" for product "Clamav" and version "0.88.7_p1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90 Search vendor "Clamav" for product "Clamav" and version "0.90" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90 Search vendor "Clamav" for product "Clamav" and version "0.90" | rc1 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90 Search vendor "Clamav" for product "Clamav" and version "0.90" | rc1.1 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90 Search vendor "Clamav" for product "Clamav" and version "0.90" | rc2 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90 Search vendor "Clamav" for product "Clamav" and version "0.90" | rc3 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90.1 Search vendor "Clamav" for product "Clamav" and version "0.90.1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90.1_p0 Search vendor "Clamav" for product "Clamav" and version "0.90.1_p0" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90.2 Search vendor "Clamav" for product "Clamav" and version "0.90.2" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90.2_p0 Search vendor "Clamav" for product "Clamav" and version "0.90.2_p0" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90.3 Search vendor "Clamav" for product "Clamav" and version "0.90.3" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90.3_p0 Search vendor "Clamav" for product "Clamav" and version "0.90.3_p0" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.90.3_p1 Search vendor "Clamav" for product "Clamav" and version "0.90.3_p1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.91 Search vendor "Clamav" for product "Clamav" and version "0.91" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.91 Search vendor "Clamav" for product "Clamav" and version "0.91" | rc1 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.91 Search vendor "Clamav" for product "Clamav" and version "0.91" | rc2 |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.91.1 Search vendor "Clamav" for product "Clamav" and version "0.91.1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.91.2 Search vendor "Clamav" for product "Clamav" and version "0.91.2" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.91.2_p0 Search vendor "Clamav" for product "Clamav" and version "0.91.2_p0" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.92 Search vendor "Clamav" for product "Clamav" and version "0.92" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.92.1 Search vendor "Clamav" for product "Clamav" and version "0.92.1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.92_p0 Search vendor "Clamav" for product "Clamav" and version "0.92_p0" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.93 Search vendor "Clamav" for product "Clamav" and version "0.93" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.93.1 Search vendor "Clamav" for product "Clamav" and version "0.93.1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.93.2 Search vendor "Clamav" for product "Clamav" and version "0.93.2" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.93.3 Search vendor "Clamav" for product "Clamav" and version "0.93.3" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.94 Search vendor "Clamav" for product "Clamav" and version "0.94" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.94.1 Search vendor "Clamav" for product "Clamav" and version "0.94.1" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | 0.94.2 Search vendor "Clamav" for product "Clamav" and version "0.94.2" | - |
Affected
|