CVE-2007-3725
The RAR VM (unrarvm.c) in Clam Antivirus (ClamAV) before 0.91 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive, resulting in a NULL pointer dereference.
- Affected products
- Clamav
- Clam Anti-virus Clamav
- = 0.15, 0.20, 0.21, 0.22, 0.23, 0.24, 0.51, 0.52, 0.53, 0.54, 0.60, 0.60p, 0.65, 0.67, 0.68, 0.68.1, 0.70, 0.71, 0.72, 0.73, 0.74, 0.75, 0.75.1, 0.80, 0.80_rc1, 0.80_rc2, 0.80_rc3, 0.80_rc4, 0.81, 0.81_rc1, 0.82, 0.83, 0.84, 0.84_rc1, 0.84_rc2, 0.85, 0.85.1, 0.86, 0.86.1, 0.86.2
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 7.7% (94th percentile)
- NVD status
- Modified
- Published
- 2007-07-12
CVE-2007-3725 at NVD
1 known exploit for CVE-2007-3725
Proof-of-concept code and exploit modules indexed by Sploitus