ClamAV 0.80 and earlier allows remote attackers to bypass virus scanning via a base64 encoded image in a data: (RFC 2397) URL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Clamav | Clam_anti-virus | 0.51 (including) | 0.51 (including) |
Clamav | Clam_anti-virus | 0.52 (including) | 0.52 (including) |
Clamav | Clam_anti-virus | 0.53 (including) | 0.53 (including) |
Clamav | Clam_anti-virus | 0.54 (including) | 0.54 (including) |
Clamav | Clam_anti-virus | 0.60 (including) | 0.60 (including) |
Clamav | Clam_anti-virus | 0.65 (including) | 0.65 (including) |
Clamav | Clam_anti-virus | 0.67 (including) | 0.67 (including) |
Clamav | Clam_anti-virus | 0.68 (including) | 0.68 (including) |
Clamav | Clam_anti-virus | 0.68.1 (including) | 0.68.1 (including) |
Clamav | Clam_anti-virus | 0.80 (including) | 0.80 (including) |
Clamav | Ubuntu | dapper | * |
Clamav | Ubuntu | devel | * |
Clamav | Ubuntu | edgy | * |
Clamav | Ubuntu | feisty | * |