CVE-2008-1835

Publication date 16 April 2008

Last updated 24 July 2024


Ubuntu priority

ClamAV before 0.93 allows remote attackers to bypass the scanning enging via a RAR file with an invalid version number, which cannot be parsed by ClamAV but can be extracted by Winrar.

Status

Package Ubuntu Release Status
clamav 9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Fixed 0.94.dfsg.2-1ubuntu0.3~hardy4
7.10 gutsy Ignored end of life, was needed
7.04 feisty Ignored end of life, was needed
6.06 LTS dapper
Fixed 0.94.dfsg.2-1ubuntu0.3~dapper2