CVE-2011-3627

Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 17 Nov 2011, 19:00
Last modified:06 Aug 2024, 23:37

Vulnerability Summary

Overall Risk (default)
low
18/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
2.72% LOW
3% probability +0.82%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Nov 2011, 19:00
Published
Vulnerability first disclosed
06 Aug 2024, 23:37
Last Modified
Vulnerability information updated

Description

The bytecode engine in ClamAV before 0.97.3 allows remote attackers to cause a denial of service (crash) via vectors related to "recursion level" and (1) libclamav/bytecode.c and (2) libclamav/bytecode_api.c.

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 2.72% Percentile: 86%

Techniques & Countermeasures

  • CWE-189Numeric Errors

    Weaknesses in this category are related to improper calculation or conversion of numbers.

Affected Systems

  • clamavclamav

    ≤ 0.97.2 | 0.9:rc1 | 0.90 | 0.90:rc1 | 0.90:rc1.1 | 0.90:rc2 | 0.90:rc3 | 0.90.1 | 0.90.2 | 0.90.3 | 0.91 | 0.91:rc1 | 0.91:rc2 | 0.91.1 | 0.91.2 | 0.92 | 0.92.1 | 0.93 | 0.93.1 | 0.93.2 | 0.93.3 | 0.94 | 0.94.1 | 0.94.2 | 0.95 | 0.95:rc1 | 0.95:rc2 | 0.95:src1 | 0.95:src2 | 0.95.1 | 0.95.2 | 0.95.3 | 0.96 | 0.96:rc1 | 0.96:rc2 | 0.96.1 | 0.96.2 | 0.96.3 | 0.96.4 | 0.96.5 | 0.97 | 0.97:rc | 0.97.1

References (10)